PHP Event Calendar XSS & User's Data Corruption Vulnerabilities

Risk: Low
Local: Yes
Remote: Yes

CVSS Base Score: 3.5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 6.8/10
Exploit range: Remote
Attack complexity: Medium
Authentication: Single time
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

New eVuln Advisory: PHP Event Calendar XSS & User's Data Corruption Vulnerabilities --------------------Summary---------------- eVuln ID: EV0063 CVE: CVE-2006-0657 Vendor: Softcomplex Vendor's Web Site: Software: PHP Event Calendar Sowtware's Web Site: Versions: 1.5 Critical Level: Harmless Type: Cross-Site Scripting Class: Remote Status: Unpatched. No reply from developer(s) Exploit: Available Solution: Not Available Discovered by: Aliaksandr Hartsuyeu ( -----------------Description--------------- Registered user has an ability to change his Username and Password. Username and Password isn't sanitized before being written to users.php file. This can be used to make XSS attack or corrupt users data. --------------Exploit---------------------- Available at: --------------Solution--------------------- No Patch available. --------------Credit----------------------- Discovered by: Aliaksandr Hartsuyeu ( Regards, Aliaksandr Hartsuyeu

Vote for this issue:


Thanks for you vote!


Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.

(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2023,


Back to Top