gem›turbolinks›GMS-2013-6Cross-site ScriptingXSS vulnerability for html files served up with Content-Disposition attachment headers.