Forum OpenACS Q&A: Re: Security hole in ad_form (may change behavior of ad_form to fix!)

I don't really understand what Lars' changes are, but prior to the bug-fix -- yes, this is exactly what would happen: you would delete your hard disk, say, when you look at a form that lists all the users in a select list using ad_form.