Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably involving the basket functionality.Referenceshttp://secunia.com/advisories/19592http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.htmlhttp://www.vupen.com/english/advisories/2006/1293