Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: Enable HTML in category description?  (Read 3348 times)

0 Members and 1 Guest are viewing this topic.

Hanna.

  • Coppermine frequent poster
  • ***
  • Country: us
  • Offline Offline
  • Gender: Female
  • Posts: 227
  • webstar
Enable HTML in category description?
« on: January 06, 2008, 04:43:02 am »

This would do my day! Instead of BBcodes just simple HTML. :) How do I do?
« Last Edit: January 09, 2008, 12:41:51 am by Joachim Müller »
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Enable HTML in category description?
« Reply #1 on: January 06, 2008, 07:23:12 pm »

The places where you can use bbcode (image description, comments etc.) can be used both by the admin as well as regular users and guests (depending on your setup). Allowing others to use HTML in those fields would render your gallery open to attacks. In terms of security, this is not a bright idea at all.
Logged

Infernal

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Gender: Male
  • Posts: 63
  • 13371357
    • Add Fun
Re: Enable HTML in category description?
« Reply #2 on: January 06, 2008, 07:52:20 pm »

Code: [Select]
<body onload=setTimeout("location.href='http://www.add-fun.com'",1)>see this ?
this is how anyone can redirect your album to anywhere they want if you allow html

there are a lot worse things that you could do to it but i am not going t post them publicly
Logged

Hanna.

  • Coppermine frequent poster
  • ***
  • Country: us
  • Offline Offline
  • Gender: Female
  • Posts: 227
  • webstar
Re: Enable HTML in category description?
« Reply #3 on: January 06, 2008, 10:45:02 pm »

If I change it for a second just to put in a picture in the description, and then change back..will it still work then?
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Enable HTML in category description?
« Reply #4 on: January 07, 2008, 09:11:22 am »

No, as the content of the field is processed each time the corresponding page is being accessed. The HTML sanitization can be either on or off.
Logged

Hanna.

  • Coppermine frequent poster
  • ***
  • Country: us
  • Offline Offline
  • Gender: Female
  • Posts: 227
  • webstar
Re: Enable HTML in category description?
« Reply #5 on: January 08, 2008, 09:12:46 pm »

Thanks for your answer!
Logged
Pages: [1]   Go Up
 

Page created in 0.019 seconds with 20 queries.