Software: phpkit Version: 1.6.03 others are probably affected as well. Status: Vendor has been notified weeks ago but refuses to answer or take any actions. phpkit[1] is a simple German cms / portal software written in php similar to phpbb / phpnuke and is quite popular in Germany. All session information is stored in cookies - thus a attacker can easily steal session data or hashed passwords. The forum part has _no_ protection against JavaScript, Object or Java injections - all html-tags appear in the victim's browser. Proof-of-concept code That's odd -