.Master Posted February 16, 2007 Posted February 16, 2007 Messenger.Message Title: ">[xss_code]And Preview message :) .For me in ipb 2.1.7 works. What will advise? Only it is not necessary to speak pass to 2.2 version ;)
ErwinB Posted February 16, 2007 Posted February 16, 2007 I can confirm. But it only works with MPs, so you have to be a registered user to try to get it work. But yes, it's true.You should report it to the Bug Tracker ;)
bfarber Posted February 16, 2007 Posted February 16, 2007 It only works for YOU. Why would you XSS yourself? :rolleyes:When previewing the message, it's just taking what you submitted and putting it back in the form. When you actually SUBMIT the message, it is cleaned.If you want to XSS yourself, have fun - but it certainly won't cause any harm to the forum, the site, or any of the members of the site.
bfarber Posted February 17, 2007 Posted February 17, 2007 I guess it depends upon how loose your definition is of a bug......
Mark Posted February 17, 2007 Posted February 17, 2007 I suppose the preview is not a preview of what is actually being sent, so that is a bug.Surely everything that will be done to the message should be done to the message in the preview? Otherwise it's not a preview of what's being sent, it's just what you typed displayed in a blue box instead of a white one.
bfarber Posted February 19, 2007 Posted February 19, 2007 *sighs*It is taking EXACTLY (without ANY conversions) what submitted the first time and putting it back in the form fields - has nothing to do with the preview. What is previewed IS actually run through the cleaner.Type in PMHit preview buttonPreviewed text is run through parser and displayedWhat you submitted is then put back in the form fields - we can't take the converted content and put in the form field (that would break what you submitted) so we take what you originally submittedYou can submit it as a bug if you really feel so inclined, but I'll tell you - it's not high up on the priority scale. ;)
ErwinB Posted February 20, 2007 Posted February 20, 2007 But it's still a bug as it's not working properly...
princetontiger Posted February 20, 2007 Posted February 20, 2007 But there are plenty of other problems to resolve. I agree with bfarber.
Recommended Posts
Archived
This topic is now archived and is closed to further replies.