A malicious attacker may inject scripts into the Oracle Siebel CRM application. Exploitation of this vulnerability results in the execution of arbitrary code using a malicious link.
http://example.com/htim_enu/start.swe/?>'"><script>alert('XSS by Lament')</script>
Disclosure Timeline:
Jan 2009 Vulnerability found
Jan 2009 Vendor Notification
Feb 2010 Public Disclosure