Homepage: Affected files: * Profile input boxes: - City input * Registering * Viewing Birthdays * Adding a friend * Viewing people online ----------------------------------------------- XSS with cookie disclosure via inviting friends:">">">">">'>'>'><"< "<"<'<'<' XSS vuln with cookie disclosure via "City" input box on profile: Data isnt properly sanatized before being generated. In one part of the site its output as full code on the screen (tested using tags, with