[Security-news] SA-CONTRIB-2012-147 - FileField Sources - Cross Site Scripting (XSS)