source: https://www.securityfocus.com/bid/24157/info Digirez is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks. Digirez 3.4 is vulnerable to these issues. http://www.example.com/room/info_book.asp?Room_name='> http://www.example.com/room/week.asp?curYear='>