MyBB Community Forums
A potential security issue - Printable Version

+- MyBB Community Forums (https://community.mybb.com)
+-- Forum: 1.8 Support (https://community.mybb.com/forum-175.html)
+--- Forum: General Support (https://community.mybb.com/forum-176.html)
+--- Thread: A potential security issue (/thread-166895.html)



A potential security issue - expat - 2015-02-11

The following errors were encountered:
A potential security issue was found in the template. Please review your changes or contact the MyBB Group for support.

i am trying to create new template.

how can i solve this thanks?


RE: A potential security issue - mmadhankumar - 2015-02-11

maybe some errors in the php code... you can post the content of the template you are trying to create, so someone can check and correct it...


RE: A potential security issue - dragonexpert - 2015-02-12

It only accepts certain types of variables in a template or you will be unable to save the template. Pasting the template here will make us figure out exactly where it doesn't like it. I do invite you to take a look at my theme variables plugin because it does have many control options for what appears.


RE: A potential security issue - expat - 2015-02-13

(2015-02-12, 02:17 PM)dragonexpert Wrote: It only accepts certain types of variables in a template or you will be unable to save the template.  Pasting the template here will make us figure out exactly where it doesn't like it.  I do invite you to take a look at my theme variables plugin because it does have many control options for what appears.

what in the premium plugin? what are these variables you can use, but why no conditionals?


RE: A potential security issue - Leefish - 2015-02-13

$ symbols incorrectly escaped will cause this issue; same with incorrect use of the [] characters. Post the code; we aren't going to steal it Toungue


RE: A potential security issue - Crazycat - 2015-02-13

* Crazycat is now in ninja mode !


RE: A potential security issue - dragonexpert - 2015-02-13

(2015-02-13, 12:46 PM)expat Wrote:
(2015-02-12, 02:17 PM)dragonexpert Wrote: It only accepts certain types of variables in a template or you will be unable to save the template.  Pasting the template here will make us figure out exactly where it doesn't like it.  I do invite you to take a look at my theme variables plugin because it does have many control options for what appears.

what in the premium plugin? what are these variables you can use, but why no conditionals?

You can't write your own conditionals, but several predefined options exist. Being able to use Regex in variables, the arrays $mybb->user and $mybb->usergroup in replacements are among my favorite features.
Basic Features
Premium Features


RE: A potential security issue - expat - 2015-02-13

nothing special LOL

I copied from the plugin and it had escape characters (\)