6.8
CVSSv2

CVE-2006-6669

Published: 20/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the format parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

webcalendar webcalendar 1.0.4

Vendor Advisories

It was discovered that WebCalendar, a PHP-based calendar application, performs insufficient sanitising in the exports handler, which allows injection of web script For the old stable distribution (sarge) this problem has been fixed in version 0945-4sarge7 The stable distribution (etch) no longer contains WebCalendar packages For the unstable d ...