[eluser]pam81[/eluser]
Hi all, i have a form on my site where the users can upload images so i would like to know how to prevent xss attack with images.
[eluser]skunkbad[/eluser]
I believe the best solution is to host your images from a second domain, or possibly a sub-domain. Most browsers have a same domain script execution policy (that's probably not the technical explanation, but you get me?)