I've discovered XSS bugs in several big german communities. All these communities use a cookie based authentification so its possible to inject script code to steal users cookies. All vendors have been informed. 1. giga.de - NBC GIGA Community ************* Affected: Whole Comment-System Example: http://www.giga.de/news/comments/index.php?id=XXXXXX&newstypid=XXXXX">alert("foo"); 3. autoscout24.de - online car market ************* Affected: All offering sites Example: http://www.autoscout24.de/home/index/detail.asp?ts=XXXXXXX">