To reply quickly to your second comment, the reason that the HTML comment vulnerability doesn't work any more is because I sent in a patch for it, some time ago. I am a firm believer in the mantra that "code speaks louder than words." I thought I had made this quite clear.
Sorry for the misunderstanding.