CVE-2018-5671 – Booking calendar, Appointment Booking System <= 2.1.7 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-5671
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter. Se ha descubierto un problema en el plugin booking-calendar 2.1.7 para WordPress. Existe XSS mediante el parámetro extra_field1[items][field_item1][price_percent] en wp-admin/admin.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/booking-calendar.md https://wpvulndb.com/vulnerabilities/9012 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-5670 – Booking calendar, Appointment Booking System <= 2.1.7 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-5670
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter. Se ha descubierto un problema en el plugin booking-calendar 2.1.7 para WordPress. Existe XSS mediante el parámetro sale_conditions[count][] en wp-admin/admin.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/booking-calendar.md https://wpvulndb.com/vulnerabilities/9012 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-18555 – Booking Calendar - Clockwork SMS <= 1.0.5 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-18555
The booking-sms plugin before 1.1.0 for WordPress has XSS. El plugin booking-sms anterior a 1.1.0 para WordPress tiene XSS. The Booking Calendar - Clockwork SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘to’ parameter in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://wordpress.org/plugins/booking-sms/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-2151
https://notcve.org/view.php?id=CVE-2017-2151
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Booking Calendar versiones 7.1 y anteriores, que permitiría a un atacante remoto inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://jvn.jp/en/jp/JVN54762089/index.html http://wpbookingcalendar.com/changelog • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-2150
https://notcve.org/view.php?id=CVE-2017-2150
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter. Vulnerabilidad de salto de directorio en Booking Calendar versioes 7.0 y anteriores, que permitiría a un atacante remoto leer ficheros arbitrarios a través de un parámetro captcha_chalange especialmente manipulado. • http://jvn.jp/en/jp/JVN18739672/index.html http://wpbookingcalendar.com/changelog • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •