Vanilla open source was terminated 1 January 2025 by Higher Logic. See this announcement for more information.
HTML Formatter Exploit
data:image/s3,"s3://crabby-images/fe8ab/fe8ab867bf21c8189c7276aa07e53fd8ba409e9a" alt="NickE"
Just as an example. The code used is
Looking through the HTML Formatter's code, I noticed it didn't replace a lot of the possible events one could hide javascript in. I'd recommend replacing all on* attributes in each tag with html entities, or just removing them all together.
<img src="blabla.png" onerror="alert('Hello There');" width=0 height=0>
Looking through the HTML Formatter's code, I noticed it didn't replace a lot of the possible events one could hide javascript in. I'd recommend replacing all on* attributes in each tag with html entities, or just removing them all together.
data:image/s3,"s3://crabby-images/cf1b1/cf1b166d852bbdad1e657acd108ba9be3fa8e917" alt="image"
0
This discussion has been closed.
Comments
$String = preg_replace("#<(.*) on(.*)=(.*)>#si", "<\\1 on\\2=\\3>", $String);
$String = preg_replace(array("<(.*?)on(.*?)>", "<(.*?)On(.*?)>"), array("\\1on\\2", "\\1Ln\\2"), $String);
Whoops, that replaces all 'o's now. Hmm... this is getting annoying.
Click Me
So that's three bugs discovered so far, hopefully all fixed in this revision.
no wonder it didn't work
*gives mark donuts