Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.Referenceshttp://secunia.com/advisories/38793http://packetstormsecurity.org/1002-exploits/arisg5-xss.txthttp://osvdb.org/62665http://www.securityfocus.com/archive/1/509758/100/0/threadedhttp://www.securityfocus.com/bid/38441http://www.securityfocus.com/archive/1/509770/100/0/threaded