[imp] 2.2.4-cvs forces charset encoding in HTTP headers

Chuck Hagenbuch chuck@horde.org
Mon, 30 Oct 2000 14:36:17 -0500


Quoting Alain Fauconnet <alain@cscoms.net>:

> That's  why I still this that this "use US english messages, don't mess
> with encoding" locale setting would be a good idea.

The only problem is that not setting a charset can be a security problem in
some cases. See the whole mess of the cross-site-scripting vulnerabilities
that came out a bit ago.

-chuck

--
"You Will Be Serviced Like Never Before." - Columbia House advertisement