Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft AskMe Pro allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to search.php or the (2) typ parameter to register.php.Referenceshttp://osvdb.org/37092http://osvdb.org/37093http://lostmon.blogspot.com/2007/07/alstrasoft-multiple-products-multiple.html