tags 317739 +patch
thanks

Hey people,

I've prepared the attached patch with addresses this issue.
Jeroen, can you review? And shall we release an advisory about this or
wait for information from the phpbb-team?


Thijs
--- bbcode.php  2005-05-12 22:55:50.000000000 +0200
+++ bbcode.php.new      2005-07-12 09:45:37.122877488 +0200
@@ -198,23 +198,23 @@

        // [img]image_url_here[/img] code..
        // This one gets first-passed..
-       $patterns[] = "#\[img:$uid\]($allowed_urlschemas://[^ 
\"\n\r\t<]*?)\[/img:$uid\]#si";
+       $patterns[] = "#\[img:$uid\]($allowed_urlschemas://[^ 
`\"\n\r\t<]*?)\[/img:$uid\]#si";
        $replacements[] = $bbcode_tpl['img'];

        // matches a [url]xxxx://www.phpbb.com[/url] code..
-       $patterns[] = "#\[url\]($allowed_urlschemas://[^ 
\"\n\r\t<]*?)\[/url\]#is";
+       $patterns[] = "#\[url\]($allowed_urlschemas://[^ 
`\"\n\r\t<]*?)\[/url\]#is";
        $replacements[] = $bbcode_tpl['url1'];

        // [url]www.phpbb.com[/url] code.. (no xxxx:// prefix).
-       $patterns[] = "#\[url\]((www|ftp)\.[^ \"\n\r\t<]*?)\[/url\]#is";
+       $patterns[] = "#\[url\]((www|ftp)\.[^ `\"\n\r\t<]*?)\[/url\]#is";
        $replacements[] = $bbcode_tpl['url2'];

        // [url=xxxx://www.phpbb.com]phpBB[/url] code..
-       $patterns[] = "#\[url=($allowed_urlschemas://[^ 
\"\n\r\t<]*?)\](.*?)\[/url\]#is";
+       $patterns[] = "#\[url=($allowed_urlschemas://[^ 
`\"\n\r\t<]*?)\](.*?)\[/url\]#is";
        $replacements[] = $bbcode_tpl['url3'];

        // [url=www.phpbb.com]phpBB[/url] code.. (no xxxx:// prefix).
-       $patterns[] = "#\[url=((www|ftp)\.[^ \"\n\r\t<]*?)\](.*?)\[/url\]#is";
+       $patterns[] = "#\[url=((www|ftp)\.[^ `\"\n\r\t<]*?)\](.*?)\[/url\]#is";
        $replacements[] = $bbcode_tpl['url4'];

        // [EMAIL PROTECTED]/email] code..

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to