d0e8f692c6
fixing a major security vulnerability which allowed attackers to execute javascript via the send_to parameter