Ernesto Baschny [cron IT] wrote: > > Problem: > sys_action is able to generate links for the backend.php toolbar. The > links with a href and "&" parameters, but this is not properly escaped > (htmlspecialchars missing). +1 on reading and testing -- Stefan Galinski