Thread: Miscellaneous Hacks - Disallow HTML code in Thread Titles
View Single Post
  #34  
Old 07 Sep 2006, 21:51
steadicamop's Avatar
steadicamop steadicamop is offline
 
Join Date: Jul 2004
Real name: Jason Williams
Originally Posted by Marco van Herwaarden
Staff Note:
Unmodified vBulletin will not evaluate HTML in thread titles. Using this modification without a hack installed that has security vulnerabilities is useless.

Also installing this modification, even with a modification installed that would make your board vulnerable to this type of HTML posting in thread titles, only will give you a false sense of security since there are many other options to exploit this, even without the use of the ">" character.

Everyone is encouraged to remove or update the vulnerable modification instead of using this hack.
If this is causing issues, please delete it, I'd rather not cause confusion or issues for other members.

Jason
Reply With Quote