Back to vBulletin 3.6 Add-ons

Disallow HTML code in Thread Titles
Mod Version: 1.01, by steadicamop

This modification is in the archives.
vB Version: 3.6.0 Rating: (0 vote - 0 average) Installs: 20
Released: 04 Sep 2006 Last Update: 04 Sep 2006 Downloads: 83
Not Supported Code Changes  

Disallow HTML code in Thread Titles v1.01

Quote by Staff Note
Staff Note:
Unmodified vBulletin will not evaluate HTML in thread titles. Using this modification without a hack installed that has security vulnerabilities is useless.

Also installing this modification, even with a modification installed that would make your board vulnerable to this type of HTML posting in thread titles, only will give you a false sense of security since there are many other options to exploit this, even without the use of the ">" character.

Everyone is encouraged to remove or update the vulnerable modification instead of using this hack.

Marco van Herwaarden.
By Jason Williams/Andrew Calderbank
03/09/2006

Recently there has been a spate of members posting html redirection code in thread titles, which when parsed on the forum homepage runs and redirects to whatever site they insert into the title.

This code simply disallows the characters < and > from being used in the thread titles, this is also is checked when editing the post.

It's fairly simple but puts to and end members signing up and posting redirect links. I don't know whether you'd class this as a hack or bug fix, but I hope this helps other members who are frustrated with this issue.

2 file edits
1 new phrase

Should be fairly straightforward to install.

**ALWAYS BACK UP FILES BEFORE YOU EDIT THEM!!**

v1.00

Original release

v1.01

Slight code update

Download

This modification is archived, downloads are still allowed.

File Type: %1$s Disallow HTML in Thread Titles.txt (1.9 KB, 267 downloads)


vblts.ru supports vBulletin®, 2022-2025