source: https://www.securityfocus.com/bid/52085/info F*EX is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to execute arbitrary script on the affected server and steal cookie-based authentication credentials. Other attacks are also possible. http://www.example.com/fup [id parameter] http://www.example.com/fup [to parameter] http://www.example.com/fup [from parameter]