Just a thought from a security newbie... does/can wicket require POST for form submissions? Would that prevent the issue of embedding the evil param values in the src of an image?

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to