Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.Referenceshttp://www.securityfocus.com/bid/33131https://www.exploit-db.com/exploits/7680http://securityreason.com/securityalert/4890