Hi, Am 15.07.2010 21:29, schrieb Dmitry Dulepov: > > Next somebody calls your page with some<script>...</script> as a > parameter, this gets cached and you get a very nice XSS... That was also my first thought :-) Regards, Christopher