Go Back   vb.org Archive > vBulletin 5 Connect Discussion > vB5 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 03-12-2015, 10:07 PM
shimei shimei is offline
 
Join Date: Feb 2015
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ForceHSS View Post
Can you post some screenshots with the code breaking and without and a link to your site so someone can give you the correct code if they can

Here's the result of having posted between either [ code ] or [ html ] tags as Lynne suggested. As you can see the entire site is wrecked (blank).



--------------- Added [DATE]1426201908[/DATE] at [TIME]1426201908[/TIME] ---------------

and here it is before I enter the code:



--------------- Added [DATE]1426202159[/DATE] at [TIME]1426202159[/TIME] ---------------

Quote:
Originally Posted by Replicant View Post
If you are posting just the code in the original post, it probably will break the page since there is no closing tag for the table. If you want to view the raw html in the post, have you tried the noparse bbcode?
Code:
[noparse]<!--added table -->
<table class="forum-list-container stretch catspace">[/noparse]
Hello Replicant,

Thank you for your support. I have not, my concern at this point is that anyone can enter code into the browser by creating a thread or replying to a post and wrecking the site.

At this point, I'm hoping someone will tell me how to find the post in the database once the site has been wrecked?

Of course, I think this needs be looked at, and I was wondering if others are having this issue or is it my site alone? I am using VB 5.1.5. I am nervous about posting a link to my site here, all I need is for someone to to do this or keep doing it. My site would be down until this is fixed.

Thanks,
Shim
Reply With Quote
  #12  
Old 03-12-2015, 10:18 PM
Replicant's Avatar
Replicant Replicant is offline
 
Join Date: Sep 2014
Location: Phoenix, Az. USA
Posts: 485
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Post the source from your post that is breaking the page here so we can see what you are doing.
Reply With Quote
  #13  
Old 03-12-2015, 10:21 PM
shimei shimei is offline
 
Join Date: Feb 2015
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I was copying this page to my forum section where I track the mods I have done to the site. I performed this mod successfully then created a thread and posted this page as a record of my changes. That's when I discovered I could wreck the site through entering any of this code into the browser/thread/post.

https://vborg.vbsupport.ru/showthread.php?t=309785
Reply With Quote
  #14  
Old 03-12-2015, 10:31 PM
Wayne Luke's Avatar
Wayne Luke Wayne Luke is offline
Senior Member
 
Join Date: Jan 2002
Location: Southern California
Posts: 1,694
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I tried to recreate this issue on a fresh installation of vBulletin 5.1.5 with no modifications. Using the [html] tags I get this result:



Using no BBCODE, I do get issues so that will need to be checked and tested more but it doesn't break the entire site. Here is what is does if no BBCode is used:



In both occurrences, the Can Use HTML permission is off globally for Administrators.

Though if you've made other changes to the templates and the above code is compounded on errors that browsers could work around, then this could cause more issues.
Reply With Quote
Благодарность от:
Lynne
  #15  
Old 03-12-2015, 10:41 PM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

As HTML seems to work for Wayne then it must be something you installed like a custom plugin or an edit to a template revert any templates and disable all plugins then test
Reply With Quote
  #16  
Old 03-12-2015, 11:05 PM
shimei shimei is offline
 
Join Date: Feb 2015
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ForceHSS View Post
As HTML seems to work for Wayne then it must be something you installed like a custom plugin or an edit to a template revert any templates and disable all plugins then test
Hello ForceHSS,

Thank you for taking the time to respond. I noticed Wayne said:

Quote:
Using no BBCODE, I do get issues so that will need to be checked and tested more but it doesn't break the entire site. Here is what is does if no BBCode is used:
Later tonight I'll delete that mod and see if the issue is less than breaking the website. Perhaps they are related, that is having done the mod and then posting similar coding in a thread?

Thank you and I'll post the results.

Shim
Reply With Quote
  #17  
Old 03-12-2015, 11:23 PM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

If you are going to remove the xml of a custom plugin also remove the files as well
Reply With Quote
  #18  
Old 03-13-2015, 01:18 AM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

As Wayne said, I had no issues posting using the html code tag. If you are, then something else is amiss.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:00 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04949 seconds
  • Memory Usage 2,241KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_code
  • (4)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (8)post_thanks_box
  • (1)post_thanks_box_bit
  • (8)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (8)post_thanks_postbit_info
  • (8)postbit
  • (8)postbit_onlinestatus
  • (8)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete