Not sure if $taboo was getting sanitized or not. Possibly an SQL injection vulnerability that allows maliciously crafted group names to inject SQL at a later date when the group CP is loaded. Unconfirmed, theoretical fix.
#devkit {
position: absolute;
top: -385px; right: 0;
width: 640px; height: 390px;
border: 1px solid black;
z-index: 10000;
}
.devkitup {
top: -385px !important;
}
.devkitdown {
top: 0 !important;
}