[Esd-l] INCLUDEPICTURE check

Brett Glass brett at lariat.org
Thu Oct 31 08:47:01 PST 2002


At 02:49 PM 10/30/2002, Simon Matthews wrote:

>IIRC, this check is to stop stealing of files on disk. However in the example that I saw, the picture URL referred to an external website.

Which means that it should *at least* be "defanged," if not quarantined, to prevent snooping -- just like an image tag.

--Brett



More information about the esd-l mailing list