CVE-2006-3933
Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.2.2 allows remote authenticated users to inject arbitrary web script or HTML via the message body.
Date published : 2006-07-31
http://www.securityfocus.com/archive/1/441182/100/0/threaded