View Single Post
  #28  
Old 17th July 2008, 13:15
Villen Villen is offline
Member
 
Join Date: Jul 2008
Posts: 1
Default re: TS SE v5.1 NULLED
I've found XSS at processing BB codes.
Vulnerable tag is "[url]"

Code:
click me
As the decision I have made compulsory replacement & on & in function format_comment
before call htmlspecialchars_uni.

Incidentally, anybody knows why htmlspecialchars_uni passes &#digit; ?

sorry for my english, prompt :)
Reply With Quote