ihavenoface / 4chan-x

Adds cute bloat.
https://4chan-x.org
Other
22 stars 14 forks source link

Javascript from archives #343

Open ccd0 opened 9 years ago

ccd0 commented 9 years ago

The way posts are retrieved from the archives allows a malicious archive to inject Javascript into the page through the name, subject, and various other fields. Fortunately this is much less scary with #341 fixed.