After logging in the page redirects to the referer url without any validation:
You will get redirected to <script>alert(1)</script> in 5 seconds.
Tsktsktsk, that's not how I built it. Gizmooooore!!!!
i am totally guilty for that Smile

the problem has been fixed now.

btw: this xss was a very poor attack vector ;)
