ایران سرور
وجود در : تمامی ورژن ها (+ 7.3)

درجه خطر : متوسط

روش عمل :

1- فایل engine/classes/parse.class.php رو باز کنید و عبارت زیر رو پیدا کنید :

        $find= array(
                    '/about:/si',
                    '/vbscript:/si',
                    "'\[quote\]'si",
                    "'\[quote=(.+?)\]'si",
                    "'\[/quote\]'si",
                    );

        $replace=array(
                      "about<b></b>:",
                      "vbscript<b></b>:",
                      "<!--QuoteBegin--><div class=\"quote\"><!--QuoteEBegin-->",
                      "<!--QuoteBegin \\1 --><div class=\"title_quote\">{$lang['i_quote']} \\1</div><div class=\"quote\"><!--QuoteEBegin-->",
                      "<!--QuoteEnd--></div><!--QuoteEEnd-->",
                      );


2- کدی که پیدا کردید رو پاک و کد زیر رو جایگزین کنید :

        $find= array(
                    '/about:/i','/vbscript:/i','/onclick/i','/onload/i','/onunload/i','/onabort/i',
                    '/onerror/i','/onblur/i','/onchange/i','/onfocus/i','/onreset/i','/onsubmit/i',
                    '/ondblclick/i','/onkeydown/i','/onkeypress/i','/onkeyup/i','/onmousedown/i',
                    '/onmouseup/i','/onmouseover/i','/onmouseout/i','/onselect/i','/javascript/i',
                    "'\[quote\]'si",
                    "'\[quote=(.+?)\]'si",
                    "'\[/quote\]'si",
                    );

        $replace=array(
                      "&#097;bout:","vbscript<b></b>:","&#111;nclick","&#111;nload","&#111;nunload",
                      "&#111;nabort","&#111;nerror","&#111;nblur","&#111;nchange","&#111;nfocus",
                      "&#111;nreset","&#111;nsubmit","&#111;ndblclick","&#111;nkeydown","&#111;nkeypress",
                      "&#111;nkeyup","&#111;nmousedown","&#111;nmouseup","&#111;nmouseover",
                      "&#111;nmouseout","&#111;nselect","j&#097;vascript",
                      "<!--QuoteBegin--><div class=\"quote\"><!--QuoteEBegin-->",
                      "<!--QuoteBegin \\1 --><div class=\"title_quote\">{$lang['i_quote']} \\1</div><div class=\"quote\"><!--QuoteEBegin-->",
                      "<!--QuoteEnd--></div><!--QuoteEEnd-->",
                      );


موفق باشید ! flower


AHMAD-SE، peymandavati و vahid_esp و 17 نفر دیگر تشکر کرده‌‌اند.

اطلاعات

برای ارسال نظر، باید در سایت عضو شوید.