Bug 16587 - opac-sendbasket.pl is open to XSS