Well yeah but I was wondering if that was possible to bypass ( the translation of < to < and > to > )
Also, I was once part of a forum that made HTML comments for every thread name and post body. It was ridiculous. All you had to do was type "-->" and then inject any HTML code you wanted, and of course CSS and Javascript if you wanted. Haha just thought I'd share that.
Example:
thread name was "--> <style type="text/css"> blah blah <!--"
<!-- thread name -->
<!-- --> <style type="text/css"> blah blah <!-- -->
Last edited by 1100; February 9th, 2010 at 06:19..
|