Summary: Using url.parse() in security sensitive checks is dangerous as an arbitrary hostname can be spoofed via javascript: URIs.
確定! 回上一頁