Forum Moderators: coopster
Is there anything we could server side?
In the meanwhile I am turning off on each client's domain the user PDF uploading capability (where it is allowed) and restrict to the domain admin side that capability.
If you are any good at mod_rewrite then perhaps you could write a peice of code that disallows #whatevername=javascript: etc from the end of the string?
I'm not sure but thanks for reminding people about this problem, i really don't think alot of people are going to or will understand the concept of this problem.