Hello Bugtraq! I want to warn you about Cross-Site Scripting vulnerability in E107. Which I found at 31.01.2009 and disclosed recently. XSS: At page for sending news to email (http://site/email.php?news.1) it's possible to conduct XSS attack via Referer header. Particularly it can be done via flash. Referer: '> Vulnerable are E107 0.7.16 and previous versions (all versions). I mentioned about this vulnerability at my site (http://websecurity.com.ua/3528/). Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua