Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.


Subject: Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.
6763945597

1812975536


even in the browser tab:

8943905888


But not in "POST REPLY" I mean normal reply...

1981736027

0572942592


Why? :oops:

Subject: Re: Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.
Hi;

It is done to avoid HTML injection, but this one case needs to be smarter -- we need to differentiate between a value that could be from an attacker or from a trusted source.

Profile PM  
Subject: Re: Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.
Informpro wrote: [View Post]
Hi;

It is done to avoid HTML injection, but this one case needs to be smarter -- we need to differentiate between a value that could be from an attacker or from a trusted source.
I'm not sure if I understood you. I think you are saying you need to check this feature, aren't you? :mryellow:

Subject: Re: Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.
Hi,

Yes, I am saying we are trying to be safe, but we are too safe because of this.

Profile PM  
Subject: Re: Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.
Informpro wrote: [View Post]
Hi,

Yes, I am saying we are trying to be safe, but we are too safe because of this.
So it's better if we don't use this quotes in the titles, isn't it? Is that what you mean?

Subject: Re: Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.
I will fix the issue in Quick Reply, but I won't fix it on page title, since injections may be possible.

I'm sure I added all these fixes because of security reasons in the past.

Subject: Re: Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.
Mighty Gorgon wrote: [View Post]
I will fix the issue in Quick Reply, but I won't fix it on page title, since injections may be possible.

I'm sure I added all these fixes because of security reasons in the past.

I got it... Thanks for all, avatar Mighty Gorgon

Subject: Re: Using Quotes (") In The Topic Title, It Shows This Signs (") In The Quick Reply.
Hi, God bless you, guys!


Page 1 of 1


  
You cannot post new topics
You cannot reply to topics
You cannot edit your posts
You cannot delete your posts
You cannot vote in polls
You cannot attach files
You can download files
You cannot post calendar events

   

This is a "Lo-Fi" version of our main content. To view the full version with more information, formatting and images, please click here.

Powered by Icy Phoenix based on phpBB
Generation Time: 0.5169s (PHP: 5% SQL: 95%)
SQL queries: 17 - Debug Off - GZIP Enabled