This Vulnerability works even when you put your script (<img src="javascript:alert('Executed from ' + top.location)" >) in nickname and you can insert HTML codes in Nickname and Lastname.
Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.