The Register exposed this ! Cross-site Scripting (XSS) vulnerabilities allow attackers to steal user authentication cookies from AmericanExpress.com – According to an independent vulnerability assessment firm… the XSS bug still remains unfixed !! To read more…follow this link: