[imp] No Inline Images.
Bill Tihen -- Information Technology
bill@mail.tasis.ch
Wed, 08 Nov 2000 18:07:45 +0100 (CET)
This is what I was indeed refering to. However, I am not sure any more of the
situations where this is a problem (maybe it isn't a problem if we are not
rendering any html tags). I will also email a friend tomorrow who knows a lot
about security issues. He explained this to me very clearly a while ago. But as
time goes by I have forgotten the details.
Bill
Quoting Rick Romero <rick@valeoinc.com>:
>
> I think he might be referring to embedded URLs.
>
> There have been 'notifications' that embedded URL's COULD be
> used to send the reader to a site that did naughty Javascript things.
> I believe the ones I saw were on the SANS mailing list.