Quote:
Originally Posted by fci
If someone's username, for example, is </er> it is rendered as html. could lead to an interesting exploit... needs some htmlentities() loving
|
Aside from the fact that this was patched in the 1.1 release, the Ventrilo client/server packages do not allow specific characters in usernames as well they have character length limits. So, unless someone writes a custom Ventrilo client and/or server with these restrictions removed, the exploit is basically theoretical.