Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.Referenceshttp://www.securityfocus.com/bid/27162http://hackerscenter.com/archive/view.asp?id=28145http://www.securityfocus.com/archive/1/485836/100/200/threadedhttp://secunia.com/advisories/28284http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt