This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#1 2012-01-08 10:54:43

waveOSBeta
Scratcher
Registered: 2009-12-08
Posts: 1000+

Whoa!

Anybody using the image userscript, look at this!

[img]http://scratch.mit.edu/img/bg_button.png" onload="javascript:alert('rookwood101s image support script is not XSS secure, it is better to disable it!');" /><img src="[/img]

[i//mg]http://scratch.mit.edu/img/bg_button.png" onload="javascript:alert('rookwood101s image support script is not XSS secure, it is better to disable it!');" /><img src="[/i//\\mg]

Last edited by waveOSBeta (2012-01-08 11:00:44)


http://internetometer.com/image/10202.png]
New signature coming soon!  smile

Offline

 

#2 2012-01-08 10:56:16

waveOSBeta
Scratcher
Registered: 2009-12-08
Posts: 1000+

Re: Whoa!

[img]http://scratch.mit.edu/img/bg_button.png" onload="javascript:alert('rookwood101s image support script is not XSS secure, it is better to disable it!');" /><img src="[/img]

Last edited by waveOSBeta (2012-01-08 11:00:23)


http://internetometer.com/image/10202.png]
New signature coming soon!  smile

Offline

 

#3 2012-01-08 10:59:45

fungirl123
Scratcher
Registered: 2011-10-09
Posts: 1000+

Re: Whoa!

?


http://www.thebrag.com/wp-content/uploads/2011/06/GroupLove_General1_IMG_9057.jpg

Offline

 

#4 2012-01-08 11:05:50

CheckItNow12
Scratcher
Registered: 2011-05-07
Posts: 1000+

Re: Whoa!

?


http://i992.photobucket.com/albums/af47/NicolBolas_Alara/Doctor%20Who/raincry.gif

Offline

 

#5 2012-01-08 11:11:39

zippynk
Scratcher
Registered: 2011-07-23
Posts: 500+

Re: Whoa!

If you have antidote, rockwood101's browser extension that brings back forum images, those codes bring up dialog boxes.

Edit: However, I think rockwood101 fixed that bug because it might be a security vulnerability.

Last edited by zippynk (2012-01-08 11:12:23)


https://dl.dropbox.com/u/60598636/trifocal_interlude_soundcloud_button.png

Offline

 

Board footer