[/COLOR][COLOR="#0000BB"]first notes[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]php is not restricted to admin[/COLOR][COLOR="#007700"]and[/COLOR][COLOR="#0000BB"]anyone can access it directty by
browser[/COLOR][COLOR="#007700"]=>[/COLOR][COLOR="#0000BB"]an attacker can add notes witch
can be html codes[/COLOR][COLOR="#007700"]=>[/COLOR][COLOR="#0000BB"]its Stored Xss