Posted by Yogi_Bear_79 on 12/10/05 21:04
"Toby Inkster" <usenet200512@tobyinkster.co.uk> wrote in message
news:9gir63-2d8.ln1@ophelia.g5n.co.uk...
> Yogi_Bear_79 wrote:
>
>> <a href="SlideShow.htm#pt.xml" target="SlideShowFrame">PT</a>
>
> What if someone supplies a link:
>
> http://your-server.com/SlideShow.htm#http://evil.com/nasty.xml
>
> You might find that a nasty image appears in your slideshow.
>
> It's better to keep this sort of stuff server-side rather than relying on
> Javascript.
>
> --
> Toby A Inkster BSc (Hons) ARCS
> Contact Me ~ http://tobyinkster.co.uk/contact
>
Good point! Right now I am trying to rebuild the page without frames using
CSS. Then I will work on moving the script to SSI
[Back to original message]
|