Actually I have no more chance to test that since I found that vulnerability during a check for a customer. Thanks for the input however. I will check that the next time. An XSS vulnerability would indeed be nicer than a simple redirection... regards, Martin Suess