Login Register
Feds Round Up 40 Illegals in One Day on Posh Massachusetts Islands --- --- WATCH: Masked Marauders Repelled From Hollywood Hills Home “Protected by God and a Gun” --- --- Senators Lindsey Graham (R) & Richard Blumenthal (D) Threaten Russia, China Following Meeting With Ukrainian President Zelensky --- --- “They’re The Ones That Lied”: Chuck Todd Blames Democrats, Not MSM, For Biden Coverup --- --- Undercover Video Bombshell! Nevada Health & Human Services Official Reveals Loophole Hiding Trans Treatments From Parents --- --- Cat Nabbed: Why a Common Parasite May Be Contributing to the Collapse in Male Fertility --- --- California Lawyer Triggers CNN Anchor For “Misgendering” Transgender Athlete During Debate Over Men Playing Women’s Sports --- --- CDC Removes Guidance that Children and Pregnant Women Should Get COVID Vax --- --- Unlicensed Guatemalan Woman Suspected of Running Over Child on Scooter in Florida --- --- China Trade Talks Stalling over Rare-earth Minerals --- ---



[Reply]
Forum Index > Helpline
Addressing the poor forum backend
Posted on: 04-22 10:10 am
ohhihohello57

Hey, iWarg.

So I was posting a thread containing some very benign JavaScript in a to see if your forum really is XSS paradise. But after posting, I got hit with a MySQL error, which I found odd.

I decided to check on the forums if it exists anyway, and it does. But the replies counter is glitched, and when I access the thread, no post pane is shown. Not even the JavaScript I embedded works.

I URGE you to fix this and make it so that any HTML tags are escaped (not removed, because I see that the bold tags I added to the word "URGE" are now gone, but escaped as human-readable text instead of markup), as people might make more glitchy threads or get away with XSSing and screw the forum.

~ ohhihohello57

if (Nerd->Personality == (NERD_PERSON_FRONTFACING + NERD_PERSON_SMARTALEC)) { return; }
< - 1 - >

[Reply]