Jump to content

RTL Unicode Character security bug?


Recommended Posts

I would have contacted support about this but because I no longer have an active license because the fees are way too high, apparently I can't report security concerns???

I've noticed that on my installation of IPS, when trying to use the URL encoded RTL Unicode character in the URL (%E2%80%AE) in the middle of params, it's still reversing the text direction and causing issues on the site. Not sure if this will work on the example below, but after the "do=" I added the above url encoded value and it reversed it on my forum and it broke the page.

i.e. http://localhost/community/index.php?/topic/2-test/&do=‮getLastComment

Link to comment
Share on other sites

  • 4 weeks later...
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...