Author: jellochuu
Description:
The latest software upgrade at Wikipedia and other Wikimedia projects
reintroduces an old problem which allows registration of accounts containing
non-printing characters such as ­. This can allow vandals to "pretend"
to be someone else. For example, a vandal can regiser a username like
Grunt%C2%AD (not actually using %C2%AD but by placing the non-printing character
in the field...). I registered an account like this by creating a blank HTML
with only the content &­ and then Ctrl+A, Ctrl+C'ing it.
Version: 1.5.x
Severity: enhancement
URL: http://en.wikipedia.org/wiki/User:%C2%AD%C2%AD%C2%ADBug_account%C2%AD%C2%AD%C2%AD