RSS   Vulnerabilities for 'Mycalendar'   RSS

2007-02-21
 
CVE-2007-1050

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.

 

 >>> Vendor: Abledesign 4 Products
Abledesign
D-man
Mycalendar
Dynamic picture frame


Copyright 2024, cxsecurity.com

 

Back to Top