Paul M,
Thanks for your input.
We know that announcing that a vulnerability exists can cause people to go search for it and try to exploit for it. In this case, the author had been contacted multiple times, but didn't seem willing to fix the script.
After discussing this internally, vBulletin.org staff decided to announce, that there is a vulnerability. We assumed that people using this modification would in the most cases be able to temporarily remove it and announce on their forum that it was removed due to security issues.
Still, I'm sure we will be reviewing our procedure for such cases. If you would like to provide any input, feel free to PM me.
|