Yeah I know it's XSS, hence the JS.

I've been going to that site for a while, the admin knows his stuff about web security, he`s a friend of a friend.