Forum OpenACS Q&A: Re: RFC: Security policy for OpenACS (Security hole in OpenACS 5.1!)

You can 'root' a server running a default OpenACS install in ten minutes using a permissive HTML setting? That is clearly news. If this is true, wow! Can we get more information on this?