RSS Forums RSS
Please support our DaniWeb Community Feedback advertiser: Programming Forums

Message preview seems to allow unfiltered markup... XSS?

Join Date: Apr 2006
Location: Canada
Posts: 4,556
Reputation: John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all 
Rep Power: 17
Solved Threads: 284
Moderator
Featured Blogger
John A's Avatar
John A John A is offline Offline
Vampirical Moderator

Re: Message preview seems to allow unfiltered markup... XSS?

  #12  
Jul 29th, 2007
Originally Posted by The Dude View Post
OK your using Opera that might explain it....
It happened to me on both Firefox 2 and Safari 3 Beta.

Maybe Opera still executes the script locally instead of from the site?? (Im telling you 'HTML' is disabled on this site!!)

<a href="http://www.daniweb.com/forums">See what i mean?</a>

Now is that formatted correctly for you?? (It shouldnt be if it is)
The Dude, HTML is not disabled on this site. How do you think this site is displayed, then. Flash? LOL.

What happens is the BBCode parser automatically turns '<' and '>' into their HTML character equivalents, &lt; and &gt; while turning [url][/url] into actual HTML code. I suspect a slightly different parser is used for the thread preview window, because it's only plaintext. When that parser was written, the '<' and '>' parsing was probably omitted, creating the bug that Matt so nicely pointed out.

But back on topic, the bug seems to be fixed, thank you Dani!
tuxation.com - Linux articles, tutorials, and discussions
Reply With Quote  
Forums | Blogs | Tutorials | Code Snippets | Whitepapers | RSS Feeds | Advertising
All times are GMT -4. The time now is 6:28 am.
Newsletter Archive - Sitemap - Privacy Statement - Acceptable Use Policy - Contact Us
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC