Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.Referenceshttp://lostmon.blogspot.com/2005/07/clever-copy-calendarphp-yr-variable.html