Direct Web Rendering (DWR) version 2.0.1 suffers from a cross site scripting vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/68008/Advisory-DWR.pdf
Source: https://packetstormsecurity.com/files/68008/Advisory-DWR.pdf.html

