Multiple cross-site scripting (XSS) vulnerabilities in login.php in Brain Book Software Secure 1.0.20070629 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pwd parameters.
https://exchange.xforce.ibmcloud.com/vulnerabilities/35583
http://www.vupen.com/english/advisories/2007/2656
http://www.securityfocus.com/bid/25024
http://pridels-team.blogspot.com/2007/07/secure-xss-vuln.html