Not sure if $taboo was getting sanitized or not. Possibly an SQL injection vulnerability that allows maliciously crafted group names to inject SQL at a later date when the group CP is loaded. Unconfirmed, theoretical fix.
.mceItemFlash, .mceItemShockWave, .mceItemQuickTime, .mceItemWindowsMedia, .mceItemRealMedia {
border: 1px dotted #cc0000;
background-position: center;
background-repeat: no-repeat;
background-color: #ffffcc;
.mceItemShockWave {
background-image: url('../images/shockwave.gif');
.mceItemFlash {
background-image: url('../images/flash.gif');
.mceItemQuickTime {
background-image: url('../images/quicktime.gif');
.mceItemWindowsMedia {
background-image: url('../images/windowsmedia.gif');
.mceItemRealMedia {
background-image: url('../images/realmedia.gif');