In PEAR HTTPRequest2 before 2.7.0, multiple files in the tests directory, notably tests/network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.