Changeset 1673

Show
Ignore:
Timestamp:
09/04/2007 11:18:51 PM (16 months ago)
Author:
jeena
Message:

now there is no XSS hole in normal bbcode

Files:
1 modified

Legend:

Unmodified
Added
Removed
  • trunk/scripts/bbcode.php

    r1671 r1673  
    2424    // URL validieren 
    2525    if($action == 'validate') { 
    26                         if (isset($params["no_js"]) AND (stripos(trim($url), "javascript:")) === 0) return false;                
     26                        if(stripos(ltrim($url), "javascript:") === 0) return false;              
    2727                        return true; 
    2828    } 
     
    141141$bbcomments->addCode ('i', 'simple_replace', null, array ('start_tag' => '<em>', 'end_tag' => '</em>'), 
    142142                  'inline', array ('block', 'inline', 'link'), array ()); 
    143 $bbcomments->addCode ('url', 'usecontent?', 'do_bbcode_url', array ('usecontent_param' => 'default', 'no_js' => true), 
     143$bbcomments->addCode ('url', 'usecontent?', 'do_bbcode_url', array ('usecontent_param' => 'default'), 
    144144                  'link', array ('block', 'inline'), array ('link')); 
    145145$bbcomments->addCode ('quote', 'simple_replace', null, array('start_tag' => '<blockquote>', 'end_tag' => '</blockquote>'),