Hacker News new | ask | show | jobs
by john_reel 3453 days ago
If string is unescaped user input, then yes, you are.