Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.
http://www.securityfocus.com/bid/27162
http://www.securityfocus.com/archive/1/485836/100/200/threaded
http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt