![]() |
I think bbcode has it's limits. Back when I was changing up my bbcode more often than I am now, if I remember right, bbcode can't do 2 options only one. Personally I kinda thought bbcode was limited. I have wav files enabled for posting, flash files. People can post images stating both the height and width the image. I think with bbcode, you can't tell it what you want the height and the width to be. You can put an option when you are creating the bbcode, but then that option would have to be both the width and height. That is if I remember right.
I do remember one reason why I need html enabled. The smilies that I have above the text field where people type their images are clickable. I believe it's using one of Fireflys hacks. to insert the smilie into the users post it adds the image using a line like this: Code:
<img src=images/icons/icon180.gif> I think that was the main reason why I add html turned on. I do however have the following commands in my censorship area: Code:
<style </style <iframe </iframe <link </link <basefont </basefont <base </base <th </th <tfoot </tfoot <tbody </tbody <thead </thead <body </body <meta </meta <script </script <html </html <plaintext </plaintext <xmp </xmp <object <noframes <noembed <noscript <nojava onload onMouseover <fieldset :absolute style="position "position absolute; <caption |
How about this seemingly innocent thing?
Code:
<a href="#" onMouseOut="doBadStuff()"> |
Quote:
Code:
<a href="#" **********="doBadStuff()"> |
You dont understand. There are possibly literally hundreds of ways to execute Javascript on a page. Just turn off HTML and the risk will be gone.
|
Quote:
|
Because you have complete control over what HTML it uses, and it scrubs any HTML the user sends.
|
All times are GMT. The time now is 06:50 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|