two probable security holes

Remove this topic?

Refresh