OSVDB 19114 http://archives.neohapsis.com/archives/bugtraq/2005-08/0442.html usr variable XSS http://archives.neohapsis.com/archives/bugtraq/2005-10/0276.html user variable XSS Makes me wonder if one of them is a typo and this is the same issue..