There's a little vulnerability in the post section of:

Sending a malicious code will result a code working on the page that pops up...[XSS CODE HERE]


