I've discovered XSS bugs in several big german communities. All these communities use a cookie based authentification so its possible to inject script code to steal users cookies. All vendors have been informed. 1. giga.de - NBC GIGA Community ************* Affected: Whole Comment-System Example: http://www.giga.de/news/comments/index.php?id=XXXXXX&newstypid=XXXXX">