in reply to Re^6: Let users link in a javascript library (required)
in thread Let users link in a javascript library
If that remote URL is a application/javascript file, I think that versions of IE will run it, and likely within the Perlmonks security context.
If that remote URL redirects back to Perlmonks, it can alter user settings, at least if there are holes left open here where we allow setting of vital things via GET.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^8: Let users link in a javascript library (required)
by ysth (Canon) on Apr 16, 2008 at 20:12 UTC |