Page 1 of 1

Syntax Highlighter XSS

Posted: Sun May 15, 2011 3:53 pm
by jacek
The syntax highlighting mod used on this forum had an XSS bug. ... ?f=5&t=126

If anyone used this mod, you need to update to the most recent version to fix it. I believe I recommended it to someone via PM but I have forgotten who so am posting this here :D"onerror="alert('xss');[/i mg]

used to work and cause the alert to be shown.

without the spaces obviously ;)

Lucky that nobody noticed eh :lol:

EDIT: It looks like I am the only person who downloaded the fixed version. So if you know of any forums using this, go warn them !