Print Page | Close Window

Javascript problems with WWF newest forum release

Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=28978
Printed Date: 01 April 2026 at 4:04pm
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: Javascript problems with WWF newest forum release
Posted By: madpakke
Subject: Javascript problems with WWF newest forum release
Date Posted: 24 November 2010 at 4:25pm
Hey Bruce / Web Wiz Forum,
 
On my forum ive got some problems with some url links in threads.
 
Exampel:
http://www.malleforum.dk/er-det-en-l264_topic1192_post7813.html#7813" rel="nofollow - http://www.malleforum.dk/er-det-en-l264_topic1192_post7813.html#7813
 
In the answer from Vimse in that Thread, you can see this link:
http://www.datz.de/DATZ-Plus/DATZ-kompakt/L-Nummern-schon-mehr-als-20-Jahre,QUlEPTgwOTg3MiZNSUQ9NTgwOTEmVElYPTA.html?UID=C40AE9200602738DF2EA997EDDAEFFB0DE4AEA02BDF2A6FD" rel="nofollow - http://www.datz.de/DATZ-Plus/DATZ-kompakt/L-Nummern-schon-mehr-als-20-Jahre,QUlEPTgwOTg3MiZNSUQ9NTgwOTEmVElYPTA.html?UID=C40AE9200602738DF2EA997EDDAEFFB0DE4AEA02BDF2A6FD
 
Then you press is, it pop up with a failed screen and this url:
javascript:if%20%28confirm%28This%20link%20will%20take%20you%20to%20the%20URL%20http://www.datz.de/DATZ-Plus/DATZ-kompakt/L-Nummern-sch%26%23111;%20-%20is%20that%20something%20you%20want%20to%20do?%29%29%20document.location=http://www.datz.de/DATZ-Plus/DATZ-kompakt/L-Nummern-scho;
 
But if you copy paste the url into a new browser, it opens fine..
 
So am woundering if there is a bug in the WWF script or what can i do here.?
Its not the first link in theads at my forum, where we get this error..
 
Hope you guys can help me out here.
 
André



Replies:
Posted By: WebWiz-Bruce
Date Posted: 24 November 2010 at 4:40pm
It looks like the link that has been copied and pasted across contains javascript.

As javascript within a link can be used to hack both the forum, the members account, or computer to do things such as XSS , XSRF luaching malware, etc. There are security filters within the forum that will strip out this type of code from within links, but if the hidden code is complex you may end up with an unusable link,

The person copy and pasting the link should use the 'Insert Hyperlink' button on the editor toolbar to add the link that way thus inserting a 'clean' link and not one that has javascript and other hidden code that could be malcious.


-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: madpakke
Date Posted: 24 November 2010 at 8:03pm
Ahh okey Bruce,, thanks for the fast answer and the solution. Thumbs Up



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net