EasyPHPCalender script XSS

2013-04-14 / 2013-04-21
Credit: Anant
Risk: Low
Local: No
Remote: Yes
CWE: CWE-79


Ogólna skala CVSS: 4.3/10
Znaczenie: 2.9/10
Łatwość wykorzystania: 8.6/10
Wymagany dostęp: Zdalny
Złożoność ataku: Średnia
Autoryzacja: Nie wymagana
Wpływ na poufność: Brak
Wpływ na integralność: Częściowy
Wpływ na dostępność: Brak

http://www.easyphpcalendar.com/forums/showthread.php?p=45554#post45554 technical details are not issued however the two issues are pertaining to XSS in following two files in the package. index.php datePicker.php This issue affect both free version i.e. version 6. as well as commerical version < 7.0.13 Changelog visible here for v7 : http://docs7.easyphpcalendar.com/source/ChangeLog/changeLog.htm for v6 patch is listed here :http://www.easyphpcalendar.com/v6download.php as Security Patch - Released April 9, 2013<http://www.easyphpcalendar.com/files/EPC6Patch.zip> Thanks in advance. -Anant

Referencje:

http://www.easyphpcalendar.com/forums/showthread.php?p=45554#post45554
http://www.easyphpcalendar.com/files/EPC6Patch.zip
http://seclists.org/oss-sec/2013/q2/index.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top