omniHTTPD 2.10 suffers from cross site scripting vulnerabilities that could lead to session hijacking.