Description
vBulletin 4 is vulnerable to an SQL injection vulnerability, which may allow an attacker can execute malicious SQL statements that control a web application's database server.
Remediation
Upgrade to the latest version of vBulletin.
References
vBulletin 4.0.x => 4.1.2 (search.php) SQL Injection Vulnerability