CVE-2008-2398
Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.
Date published : 2008-05-21
http://www.securityfocus.com/bid/29291
http://www.securityfocus.com/archive/1/492271/100/0/threaded