Iframe element uploaded to posterous: Note that the URL is not sanitized/prefixed with a string to prevent firing the code.