source: https://www.securityfocus.com/bid/9307/info Multiple cross-site scripting vulnerabilities have been reported in L-Soft Listserv. An attacker may exploit these issues by embedding hostile HTML and script code in a link to a site hosting the software. This could permit theft of cookie-based authentication credentials or other attacks. These issues could also provide an attack vector for latent vulnerabilities in web browser software. http://www.example.com/SCRIPTS/WA-MSD.EXE?A0=&T=malware is in the zone http://www.example.com/SCRIPTS/WA-USIAINFO.EXE? A1=ind0312d&L=dosback http://www.example.com/Scripts/wa-demo.exe?A1=ind9807&L=demo