Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) message or (2) subject parameter.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/30520http://www.securityfocus.com/bid/21248http://www.zion-security.com/text/Mul_Vulnerability_DeskPro.txthttp://secunia.com/advisories/22991http://www.vupen.com/english/advisories/2006/4676http://www.osvdb.org/30671