Allowing HTML in Posts

njs12345 recently brought this to my attention in the mIRC chat room…

http://www.securitytracker.com/alerts/2002/Dec/1005803.html

I find it quite interesting. Do you know if vBulletin has fixed this security flaw? If not, I think we should probably disable HTML in posts or at least certain tags maybe?

I know in this link it says

Vulnerable Versions:


2.2.7
2.2.8

But it also has no versions under the Non-Vulnerable Versions, so I don’t know if it is fixed or not.

It should be something to look into though.

I enabled HTML in the Battle forum. I figured if any forum really requires the use of the HTML, that forum would have to be it. Besides, all the polls and results had HTML links that wouldn’t display :slight_smile: Kinda tough to work on the kirupaLab update when all the links have to be clicked on!