Hotscripts.com Homepage: http://www.hotscripts.com Effected files: search input box adding a review Editing your profile sending a author a message. Creating a new listing ---------------------------------------- XSS vuln with cookie disclosure in search input box: For a PoC try putting: <"<"<"<"