Cross-site scripting (XSS) vulnerability in logout.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter.
http://www.taskfreak.com/original/versions
http://www.securityfocus.com/bid/41221
http://www.securityfocus.com/archive/1/512078/100/0/threaded
http://secunia.com/secunia_research/2010-78/