Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
As the Flickrizer extension does not validate any information it recieves from the rss file, it is easily possible to exploit this and insert js into an account page. For an example of this see my profile. You can see how it's done by viewing the rss 'feed': http://sirnot.googlepages.com/flickr.xml
This discussion has been closed.