The issue is still unresolved by the vendor, so here is an example, still available, from their site:http://www.bitrixsoft.com/bitrix/redirect.php?event1=demo_out&event2=sm_demo&event3=pdemo&goto=http://www.xssed.com/news/29/The_dangers_of_Redirect_vulnerabilities/Obviously, the fact that I can send you to XSSed.com's fine explanation of the issue, in the context of the vendor's site, is a no-no in