Login Register
UK Patriots Hold MASSIVE London Rally & Honor Charlie Kirk! Tommy Robinson, Elon Musk, Others Gather In Demonstration Dubbed “Far-Right” By Establishment Media --- --- Pelosi: Democrats “Won’t Be Responsible” For Years Of Violent Rhetoric Against Trump --- --- Breaking! Charlie Kirk Assassin Tyler Robinson Was Reportedly Living With TRANSGENDER PARTNER --- --- Watch: X Falsely Claims “Charlie Kirk Shot By Fellow Conservative” Despite Assassin’s Leftist Views --- --- Watch: Charlie Kirk’s Assassin 100% Confirmed “Anti-Fascist” Brainwashed Leftist – Meanwhile, Leftists Claim He Was a Right Winger as Others Blame Israel --- --- Good Morning Infowars: Suspect In Fatal Stabbing Of Iryna Zarutska Confesses Details Of Brutal Murder To Family – Plus, Charlie Kirk Memorial Service Impacts Christians Worldwide --- --- Leftists Cheer Charlie Kirk’s Assassin Then Falsely Claim He Is “Right Wing” --- --- WATCH: Socialist Officials Sabotage Moment of Silence for Charlie Kirk in European Parliament --- --- NATO Kicks Off Military Drill in Response to ‘Russian Violations’ --- --- Belarus Frees 52 Political Prisoners, Gains US Sanctions Relief, Warm Letter From Trump --- ---



[Reply]
Forum Index > Helpline
Addressing the poor forum backend
Posted on: 04-22 10:10 am
ohhihohello57

Hey, iWarg.

So I was posting a thread containing some very benign JavaScript in a to see if your forum really is XSS paradise. But after posting, I got hit with a MySQL error, which I found odd.

I decided to check on the forums if it exists anyway, and it does. But the replies counter is glitched, and when I access the thread, no post pane is shown. Not even the JavaScript I embedded works.

I URGE you to fix this and make it so that any HTML tags are escaped (not removed, because I see that the bold tags I added to the word "URGE" are now gone, but escaped as human-readable text instead of markup), as people might make more glitchy threads or get away with XSSing and screw the forum.

~ ohhihohello57

if (Nerd->Personality == (NERD_PERSON_FRONTFACING + NERD_PERSON_SMARTALEC)) { return; }
< - 1 - >

[Reply]