Multiple cross-site scripting (XSS) vulnerabilities in IDE Group DVD Rental System (DRS) 5.1 before 20070801 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: it is not clear whether IDE Group updates all DRS installations in its role as an application service provider. If so, then this issue should not be included in CVE.
https://exchange.xforce.ibmcloud.com/vulnerabilities/35768
http://www.vupen.com/english/advisories/2007/2806
http://www.securityfocus.com/bid/25177
http://secunia.com/advisories/26310
http://archives.neohapsis.com/archives/fulldisclosure/2007-08/0020.html