I googled it, basically emulates a trusted site where you log in. It's not actually the trusted site though, it takes your username/pass and what not.
Oh no, I know what it is. I meant details as to where the exploit is, where it's hosted, whatever he found.
XSS is is a type of computer security vulnerability typically found in Web applications (wikipedia). To fix it, some files have to be edited and secure this thing. I can help if the admin wants.. Google it -> XSS