IMG tag

  • Thread starter Thread starter topkurs2
  • Start date Start date

topkurs2

Guest
Member
Hello.
Just found some small, but unpleasant bug or feature?
When using IMG tag, manually we can add in this tag any url, any info, not only image.
I mean
Code:

[img]http://google.com[/img]
or
Code:

[img]http://127.0.0.1[/img]
All these tags are parsing by Xenforo in such way:
bug.png
It's very unsecure. This opens the possibility for attacks, -Redacted-, disclosure of IP address...

Read more

Continue reading...
 
Top