Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.
http://www.debian.org/security/2002/dsa-109
http://sourceforge.net/mailarchive/forum.php?thread_id=464940&forum_id=6367