The Arcive of vBulletin Modifications Site. |
|
|
#1
|
|||
|
|||
|
I was reading this hack....and was wondering....why is this risky?
https://vborg.vbsupport.ru/showthread.php?p=1658551 |
|
#2
|
|||
|
|||
|
When HTML is allowed, you can post malicious code. Like iframes (which can contain virusses) and JavaScript (which can be used to obtain admin passwords).
So you create a huge XSS security leak. Only allow it if you really trust all people in that usergroup. |
![]() |
|
|
| X vBulletin 3.8.12 by vBS Debug Information | |
|---|---|
|
|
More Information |
|
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|