5 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

A vulnerability, which was classified as problematic, was found in sproctor php-calendar. This affects an unknown part of the file index.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is a2941109b42201c19733127ced763e270a357809. • https://github.com/sproctor/php-calendar/commit/a2941109b42201c19733127ced763e270a357809 https://vuldb.com/?id.215445 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-707: Improper Neutralization •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed to the "php-calendar-master/error.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. Un problema de XSS ha sido descubierto en php-calendar en versiones anteriores a 03-03-2017. La vulnerabilidad existe debido a filtración insuficiente de datos suministrados por el usuario (errosMsg) pasados a la URL "php-calendar-master/error.php". • https://github.com/jasonjoh/php-calendar/issues/4 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 18EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction parameters. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en index.php de PHP-Calendar en versiones anteriores a la v2.0 Beta7. Permiten a atacantes remotos inyectar codigo de script web o código HTML de su elección a través de los parámetros (1) description y (2) lastaction. • http://packetstormsecurity.org/1005-advisories/phpcalendar-xss.txt http://php-calendar.blogspot.com/2010/05/php-calendar-20-beta7.html http://secunia.com/advisories/33899 http://www.securityfocus.com/archive/1/511395/100/0/threaded http://www.securityfocus.com/bid/40334 http://www.vupen.com/english/advisories/2010/1202 https://exchange.xforce.ibmcloud.com/vulnerabilities/58861 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 0

SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. • http://secunia.com/advisories/15116 http://sourceforge.net/project/shownotes.php?release_id=323483 http://www.osvdb.org/15866 http://www.securityfocus.com/bid/13405 http://www.vupen.com/english/advisories/2005/0418 https://exchange.xforce.ibmcloud.com/vulnerabilities/20297 •

CVSS: 7.5EPSS: 18%CPEs: 11EXPL: 4

Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php. • https://www.exploit-db.com/exploits/43819 http://marc.info/?l=bugtraq&m=110434580716205&w=2 http://secunia.com/advisories/22516 http://securitytracker.com/id?1017107 http://sourceforge.net/project/shownotes.php?release_id=296020&group_id=46800 http://www.gulftech.org/?node=research&article_id=00060-12292004 http://www.securityfocus.com/archive/1/449397/100/0/threaded http://www.securityfocus.com/bid/12127 http://www.securityfocus.com/bid/20657 http://www.vupen.com/english • CWE-94: Improper Control of Generation of Code ('Code Injection') •