Yes, you need the keys to the kingdom (the ability to deploy compiled
Java code into the active application's classpath) in order to use the
"exploit". If you can accomplish that, the ability to provide your own
component actions is a footnote compared to what you could accomplish
otherways.

On Sat, Mar 7, 2009 at 11:39 AM, Otho <taa...@googlemail.com> wrote:
> If you revert to the official jar, how is your ComponentAction still there?
>
> And I don't actually understand, what the possible attack vector would be.
>



-- 
Howard M. Lewis Ship

Creator Apache Tapestry and Apache HiveMind

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tapestry.apache.org
For additional commands, e-mail: users-h...@tapestry.apache.org

Reply via email to