Ajeh:
The current release v1.3.9g was just released with the added Protection and, unfortunately, is too good ... so there is the need for the "white list" at this time ...
This will all be addressed in the next release ...
It takes two seconds to open a blank file and save it as:
/admin/includes/extra_configures/extra_white_list.php
You already have the directory:
/admin/includes/extra_configures/
You want to make a file called:
extra_white_list.php
and load it to the directory:
/admin/includes/extra_configures/
and in that file copy and paste the code posted in thread #52 ...
What this code is doing is excluding certain parts of the code from the extra protection that has been added in v1.3.9g from being applied to certain areas of the Admin so that when you edit the data and enter the HTML code it is not getting this extra protection as it also is protecting you against HTML code that you need to enter in some areas of the Admin ...
For ma part I have a problem that this extra-white-list.php couldn't resolve.
For exemple I have a problem with the "Shipping & returns" file, then I created extra_white_list.php in /admin/includes/extra_configures/ and it didn't work.
Inside i wrote:
$my_whitelist = array('shippinginfo'); -> didn't work
I tried with:
$my_whitelist = array('shippinginfo.php'); -> didn't work
then tried with:
$my_whitelist = array('define_shippinginfo.php'); -> didn't work
tried with:
$my_whitelist = array('define_shippinginfo'); -> didn't work
Then I read to do this with xss_whitelist.php instead of extra-white-list.php -> didn't work
Sorry, may be I missed something?
Could somebody help me?