HyperNews homepage - About HyperNews
 Next-in-Thread Next-in-Thread
 Next Message Next Message

Question user able to add HTML to title 

Forum: Instructions for Adding a Message
Date: 1998, Jul 18
From: <Anonymous>

at a hypernews message board I frequent, someone has managed to add HTML tags to the titles of messages, and has disabled the board by not closing tags on more than one occassion. normally the tags are converted to &lt; and &gt; and this is not an issue. being that the administrators might close down this board if the problem isn't resolved, I'm working trying to work with one of the administrators (who, incidentally, is not the person who set up the system and knows little about its workings) to figure out how they managed this and possibly how it can be overcome. at the least if I knew how it was done, I could post a response and close his tags until the administrator has the opportunity to delete the offending post (which in itself is a difficult task, since the unclosed tag forces the admin to save the page, edit the HTML, and then submit when deleting). has anyone else experienced this, or do you know how this could happen? being that this is a security problem I don't want to see anyone else having, if you'd rather you can speak to me by e-mail about it instead of posting here so no-one gets any ideas ;-)

any help would be much appreciated, I would hate to see this board shut down because of one person's mischief. I personally don't have access to the server, nor does the admin I'm working with (he does have password access to all articles), and we'd rather not have to bother the one who does have server access with this if it isn't necessary (there is a chance he'd rather just delete the board than have to do any problem solving on it). The Hypernews version is 1.9B5.6, however it has been altered quite a bit from the original source.

 Next-in-Thread Next-in-Thread
 Next Message Next Message
Inline:
 1 1
 All All
Outline:
 1 1
 2 2
 All All

1 Feedback: <HTML> in titles & more? ... maybe via email or direct posting by liberte@hypernews.org, 1998, Jul 18

 Add Add
to: "user able to add HTML to title"

 Members Members
 Subscribe Subscribe
 Admin Mode Admin Mode
 Show Frames Show Frames
 Help Help


HyperNews Instructions for:
|| Reading Messages || Administration of Messages || Subscribing and Unsubscribing ||
|| Adding Messages || Posting by Email || Becoming a Member ||
Earn money with Scour!
Google
 
Web www.HyperNews.org
Earn money with Scour!