Hello! I've found a XSS in Ultimate Auction <=3.67. The Vendor was informed mid October 2005! They still haven't fix the script and doesn't reply to mails. Here's a little Example: http://www.ultimate-auction.de/cgi-local/auktion/item.pl/item.pl?item= http://www.ultimate-auction.de/cgi-local/auktion/itemlist.pl?category= The bug has the BID 16239 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/