Not sure if $taboo was getting sanitized or not. Possibly an SQL injection vulnerability that allows maliciously crafted group names to inject SQL at a later date when the group CP is loaded. Unconfirmed, theoretical fix.
+ − /* CSS file for advimage plugin popup */
+ −
+ − .mceLinkList, .mceAnchorList, #targetlist {
+ − width: 280px;
+ − }
+ −
+ − .mceActionPanel {
+ − margin-top: 7px;
+ − }
+ −
+ − .panel_wrapper div.current {
+ − height: 320px;
+ − }
+ −
+ − #classlist, #title, #href {
+ − width: 280px;
+ − }
+ −
+ − #popupurl, #popupname {
+ − width: 200px;
+ − }
+ −
+ − #popupwidth, #popupheight, #popupleft, #popuptop {
+ − width: 30px;
+ − vertical-align: middle;
+ − text-align: center;
+ − }
+ −
+ − #id, #style, #classes, #target, #dir, #hreflang, #lang, #charset, #type, #rel, #rev, #tabindex, #accesskey {
+ − width: 200px;
+ − }
+ −
+ − #events_panel input {
+ − width: 200px;
+ − }