[wp-trac] Re: [WordPress Trac] #4720: Users without unfiltered_html capability can post arbitrary html

WordPress Trac wp-trac at lists.automattic.com
Wed Aug 15 16:49:55 GMT 2007


#4720: Users without unfiltered_html capability can post arbitrary html
-----------------------+----------------------------------------------------
 Reporter:  xknown     |        Owner:  anonymous
     Type:  defect     |       Status:  reopened 
 Priority:  high       |    Milestone:  2.2.3    
Component:  Security   |      Version:  2.2.2    
 Severity:  major      |   Resolution:           
 Keywords:  has-patch  |  
-----------------------+----------------------------------------------------
Comment (by Otto42):

 Question to xknown (original submitter): Have you actually done this and
 made it work? Can you provide exact reproduction details? Or is this a
 purely theoretical thing you found while looking through the code?

 Because I just tried it with a local install of 2.2.2 and was unable to
 reproduce it.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/4720#comment:11>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list