2008-10-28, 03:42 PM
G'day everyone
I haven't installed MyBB yet... I'm just checking out the .lang.php files. I saw that there is an escaped single quote in the file user_admin_permissions.lang.php that doesn't looks like it should be escaped.
File:
user_admin_permissions.lang.php
Suspect line:
$l['confirm_perms_deletion2'] = "Are you sure you wish to revoke this user\'s permissions?";
There are other cases in the .lang.php files where "user's" have not been escaped like that, so this looks like an oversight.
That said, I haven't tested it live because I haven't installed MyBB yet.
Samuel (aka leuce)
I haven't installed MyBB yet... I'm just checking out the .lang.php files. I saw that there is an escaped single quote in the file user_admin_permissions.lang.php that doesn't looks like it should be escaped.
File:
user_admin_permissions.lang.php
Suspect line:
$l['confirm_perms_deletion2'] = "Are you sure you wish to revoke this user\'s permissions?";
There are other cases in the .lang.php files where "user's" have not been escaped like that, so this looks like an oversight.
That said, I haven't tested it live because I haven't installed MyBB yet.
Samuel (aka leuce)