Since most users allow the browser to load images, an external image can be used to trigger an GET request to an arbitrary URL, and the browser sends all session cookies of the target domain to that URL. Without any interaction from the user.
While state change on the server side should not be triggered by GET requests they often are. So it's safer to forbid them.
In reply to Re^5: Let users link in a javascript library (required)
by moritz
in thread Let users link in a javascript library
by jdporter
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |