Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsForumForumBugs and Security Problems Galore!Bugs and Security Problems Galore!
Previous
 
Next
New Post
11/13/2006 1:38 PM
 

There are all sorts of bugs and security problems with these forums!!! 

For one thing, ANYONE who's posting can screw up the entire page with a <script> tag block and some JavaScript. Or even easier, some random  </table> tags. Worse than that they can do it with a signature too. 

THIS IS VERSION 3.*.*?!!!

How did it get this far without these issues being addressed?

 
New Post
11/16/2006 4:29 PM
 

SlickCoder is right!!

This is serious!! , I´ve noticed this myself too, but maybe does anyone know how to disable the HTML posting. I mean, this bug could be corrected disabling this option to the users.

Please Developers, review this issue!

 
New Post
11/16/2006 8:41 PM
 
Yes..this aint good.  css bery, bery bad.   I use the FCK Editor and I have disabled source view for all end user functionality.

Version: DNN 4.4.1
Hosting Provider: 1and1
RAISE
 
New Post
11/17/2006 2:17 AM
 
I am constantly reviewing things like this. To be honest, there is no 100% safe way to accept HTML data. What is happening here can definately be done better though.

Chris Paterra

Get direct answers to your questions in the Community Exchange.
 
New Post
11/21/2006 4:55 PM
 

frankt wrote
Yes..this aint good.  css bery, bery bad.   I use the FCK Editor and I have disabled source view for all end user functionality.

Frankt, how did you disable source view?? I really need your help on this.

Thanks

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsForumForumBugs and Security Problems Galore!Bugs and Security Problems Galore!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out