http://www.maximumpc.com/article/new...nasty_xss_flaw