Unspecified vulnerability in StoresAndCalendarsList.cgi in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to cause a denial of service via the session parameter, possibly related to format string specifiers or malformed URL encoding.
https://exchange.xforce.ibmcloud.com/vulnerabilities/28872
http://www.vupen.com/english/advisories/2006/3569
http://secunia.com/advisories/21862
http://archives.neohapsis.com/archives/fulldisclosure/2006-09/0187.html