
http://www.heise.de/security/dienste/br ... ogo_en.jpg
edit: good, embedded images don't run the JavaScript
That, and yer entire porn collection just got downloaded to Fenders comp.bork[e] wrote:ie just said omg I'm vulnerable, is that all that happens?
Here's a hint, it could execute arbitrary JavaScript, for starters. So I could probably insert some JS to read any cookies for the domain displaying the image and post them to a web server.bork[e] wrote:ie just said omg I'm vulnerable, is that all that happens?