Bingbox.com Homepage: http://www.bingbox.com Affected files: * Profile input boxes: - City input * Registering * Viewing Birthdays * Adding a friend * Viewing people online ----------------------------------------------- XSS with cookie disclosure via inviting friends: http://www.bingbox.com/go/admin/f=friends&o=invite&a=msn&t=web&wizard=start">">">">">'>'>'><"< "<"<'<'<' XSS vuln with cookie disclosure via "City" input box on profile: Data isnt properly sanatized before being generated. In one part of the site its output as full code on the screen (tested using tags, with