This BB Code has the same security flaw as the Google Maps one... You're taking the entire "src" parameter from the BB Code- there's no reason someone has to point to google- they could point to any website/domain anywhere and then run any code they wanted on your site including Flash, Java, or any other insecure code and give your users viruses or such.
You can not allow arbitrary URL's in IFRAME BB Codes...
I strongly suggest editing the code or removing this altogether.
(edited per Paul M's post)
|