Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.
http://sourceforge.net/tracker/index.php?func=detail&aid=1188735&group_id=81992&atid=564683