CVE-2011-0446: Potential XSS Problem with mail_to :encode => :javascript CVE-2011-0447: CSRF Protection Bypass OK ajacoutot@