Login Register
Carmakers Sharing Location Data with US Government without Warrants --- --- New Pfizer RSV Vaccine Linked To Premature Births in Pregnant Women --- --- Pharma Companies Knowingly Sold Blood Products Contaminated with HIV and Hepatitis C --- --- WATCH: Pro-Palestine Protesters Disrupt University Commencement Ceremony --- --- Northern Gaza In Grip of Full-Blown Famine, UN Food Agency Chief Says --- --- Long Beach Hotel Housing ‘Homeless’ Sparks Tuberculosis Outbreak as Health Emergency Declared --- --- Data Centers Hiding In ‘Spy Country’ Northern Virginia Will Need Reactor’s Worth of Power --- --- Denmark to Allow 15-Year-Olds to Get Abortions Without Parental Consent --- --- Hand of Soros: Georgian Prime Minister Denounces US Color Revolution Tactics --- --- Vehicle Crashes into White House Security Barrier, Driver Dead --- --- Gaza Camps Were Planned with Trained Activists Months in Advance --- --- Over Half of All Germans Believe They Are Being Replaced in Their Own Country --- --- “Arrest Deranged Jack Smith.” Trump Rails against Prosecutor in Classified Documents Case after Evidence-tampering Revelation --- --- “I’m Sick Myself”: CNN’s Chris Cuomo Says He Has Suffered Side Effects from COVID Shot --- --- Victory! Biden Shuts Down Controversial DHS ‘Experts’ Panel in Wake of Lawsuit --- ---



[Reply]
Forum Index > Helpline
Addressing the poor forum backend
Posted on: 04-22 10:10 am
ohhihohello57

Hey, iWarg.

So I was posting a thread containing some very benign JavaScript in a to see if your forum really is XSS paradise. But after posting, I got hit with a MySQL error, which I found odd.

I decided to check on the forums if it exists anyway, and it does. But the replies counter is glitched, and when I access the thread, no post pane is shown. Not even the JavaScript I embedded works.

I URGE you to fix this and make it so that any HTML tags are escaped (not removed, because I see that the bold tags I added to the word "URGE" are now gone, but escaped as human-readable text instead of markup), as people might make more glitchy threads or get away with XSSing and screw the forum.

~ ohhihohello57

if (Nerd->Personality == (NERD_PERSON_FRONTFACING + NERD_PERSON_SMARTALEC)) { return; }
< - 1 - >

[Reply]