Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can you explain why this is dangerous? Is it because there could be executable code in what's returned?


Yes, and since it's just a URL even if you perform an audit it could have malicious code injected at any time in the future without your knowledge.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: