Please upgrade here. These earlier versions are no longer being updated and have security issues.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.

HTML security vulnerability?

edited June 2012 in Vanilla 2.0 - 2.8

I just find a message about it's security vulnerability from,and the original report can be visit at China national vulnerability database.Anyone has an idea?



  • Can you please translate to English? My chinese is a bit 'rusty'

    There was an error rendering this rich post.

  • x00x00 MVP
    edited June 2012


    This is the same vulnerability that "Heny Hogard" posted before.

    ClarkChang why in every post you include you url? A bit shameless no? I think if you contribute a lot then folk might turn a blind eye to putting a link in your sig, if you provide something relevant to vanilla community that you yourself are providing.

    There is such a thing as 'biting the hand the feeds you', or 'sh** on your own doorstep' I don't know it they have similar expressions in Chinese.

    We are not born yesterday, this is not your first offence, it is understandable that you are trying to be helpful aswell, but there are ways and means.

    The silly thing is this doesn't work for SEO, they don't follow those links. you might get a small amount of direct of traffic, but unlikely to be useful traffic under these circumstances.

    grep is your friend.

  • @x00 thank you for your,it's a website created by stone,and i hope to do some help because i like vanilla.I'm sorry anyway.

Sign In or Register to comment.