CVE-2006-3538
Multiple cross-site scripting (XSS) vulnerabilities in demo.php in BeatificFaith Eprayer Alpha allow remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the (1) "Your name" field and (2) "Enter Prayer Request here" field.
Date published : 2006-07-12
http://www.securityfocus.com/bid/18485
http://www.securityfocus.com/archive/1/437269/100/0/threaded