Is the XSS issue covered by CVE-2007-5944 any different from that in CVE-2006-3918? Both arise from a failure to filter user-supplied input passed via an Expect header. George -- theall at tenablesecurity.com