Just discovered this great article by Robbe D. Morris: http://www.eggheadcafe.com/articles/hijacksession.asp. Worth a read if you're having trouble with your customers or if undefined errors appear.
%3escript%rcalert('lala')%3c$3e/script%c