[arch-security] [ASA-201605-25] bugzilla: cross-site scripting