(:A cross-site scripting vulnerability has been identified in AVG Antivirus.:A remote attacker could exploit it in order to execute arbitrary JavaScript or HTML code by inciting their victim into following a specially formed link.::This vulnerability stems from a lack of input users when using "<a msg=133> and <ax ys=100>" tags.::A proof of concept is available via the searcher Twitter.)