View Full Version : Read this thread
filburt1
08-27-2003, 08:17 PM
Usually "Don't read this thread" doesn't work, so...
Ignore:
test
test
test
lasto
08-27-2003, 09:26 PM
/me is dopey cause he just had to read it!
filburt1
08-28-2003, 02:52 AM
BTW, my test didn't work, so you should all be happy; otherwise I just found the biggest XSS flaw in vB ever. Actually I did find one that exists in custom-written vB codes (ones created in the admin CP) but I won't go into details.
filburt1
08-29-2003, 12:57 AM
test
assassingod
08-29-2003, 06:10 AM
Looks like its been fixed in the SQL tag as well
filburt1
08-29-2003, 10:18 AM
I've been looking at the bbcodeparse function and its child functions. There are no XSS problems, it seems, but there can be for custom vB codes (and I have yet to receive a reply): http://www.vbulletin.com/forum/showthread.php?t=81176
assassingod
08-29-2003, 12:00 PM
Looks like quite a big bug then?
filburt1
08-29-2003, 12:52 PM
Yes, provided your custom tags work like that. It seems, though, whenever I post a bug or potential bug, I always have to bump it to at least get a reply for details, confirmation, etc...
assassingod
08-29-2003, 01:02 PM
Too bad vB.com don't have a bug tracker for vB2, but seeing as there may not be any more releases of vB2.x, it would be rather pointless
filburt1
08-29-2003, 02:53 PM
I bet the problem still exists in vB3. Fancy making a test? I'm busy working on the craziest script ever for WDF (string parsing in a loop about 300,000 times).
assassingod
08-29-2003, 03:01 PM
Sure. Wow, that's a big script.
Edit: Reported, but it was deleted. Wont go into it here.
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.