|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Generate data entry and reporting .NET Web apps in minutes, straight from your database. Read our FREE whitepaper “Build Web 2.0 Applications Without Hand-Coding” Download now! |
|
#1
|
||||
|
||||
|
Post title XSS issue
Hi guys,
HTML is not being escaped in post titles. (Thread titles are fine.) I noticed this by accident in someone else's new thread. I see you've been testing HTML entities, so it might just have crept in from recent changes or something. I've posted a JS injection demo in the outhouse (pops up 2 alerts at present). This could be used to hijack accounts. I'd suggest you just find the code that outputs post titles and run it through htmlspecialchars() if there isn't already a vB formatting function it should be going through. BurningSnowman
__________________
The Mystery of the Avatar of Doom laid to rest. |
|
#2
|
||||
|
||||
|
This is fixed now, if you still see any issues please let us know.
|
![]() |
| Viewing: Dev Shed Forums > Forum Information > Suggestions & Feedback > Post title XSS issue |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|