So they let the URL specify the content-encoding? They might be
vulnerable to XSS via UTF-7 as well.
Regards,
Brian
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.