|
|
|
|
|
by spohlenz
4889 days ago
|
|
> I'm also north of 90% probable that I could weaponize it to turn any image tag on the Internet into "roots your local machine" Definitely not saying you're wrong, but I'm not convinced this is doable. Every exploit I've seen requires a request body -- how would you do that with an IMG tag? |
|
I'm actually going on a Rails security safari later, though not particularly looking to widen this/these vulnerabilities. I figure I've gotten enough out of the community over the years to contribute part of a workweek and get one more hole plugged.