"#cross-site scripting" #cookie important:1