Summary
This host is running Todayu and is prone to cross site scripting vulnerabilities.
Impact
Successful exploitation could allow execution of scripts or actions written by an attacker. In addition, an attacker may obtain authorization cookies that would allow him to gain unauthorized access to the application.
Impact Level: Application
Solution
Upgrade to version 2.1.1 or later,
For updates refer to http://www.todoyu.com/community/download
Insight
The flaw is due to failure in the 'lib/js/jscalendar/php/test.php?' script to properly sanitize user supplied input in 'lang' parameter.
Affected
Todayu version 2.1.0 and prior
References