Quote:
Originally Posted by Paul M
Really ? Isnt that exactly what [url ] and [img ] tags allow ?
@nitra1000 - please add the instructions to a text file and upload them, otherwise this is likely to get removed for having no files. Thanks.
|
OK, I should have said "you can not allow arbitrary URL's to be passed to IFRAME based BB Codes..." but surely you can see the security risk inherent in this code... If anyone is interested put the URL: http://www.juot.net/nofile.html into this code... You will get my 'red' 404 file not found custom error page... I promise you it is safe for this test but if I was someone with malicious intentions I could put dangerous code on that page and then embed it into anyone's site who allows this code.