PHP ICalendar Multiple Cross-Site Scripting Vulnerabilities
BID:21792
Info
PHP ICalendar Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 21792 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 27 2006 12:00AM |
| Updated: | Jan 04 2007 06:26PM |
| Credit: | lostmon is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
PHP iCalendar PHP iCalendar 2.0 b PHP iCalendar PHP iCalendar 2.23 rc1 PHP iCalendar PHP iCalendar 2.22 PHP iCalendar PHP iCalendar 1.1 |
| Not Vulnerable: | |
Discussion
Exploit / POC
PHP ICalendar Multiple Cross-Site Scripting Vulnerabilities
An attacker can trigger these vulnerabilities by enticing a victim user to follow a malicious URI.
Example URIs and example exploit code have been provided:
An attacker can trigger these vulnerabilities by enticing a victim user to follow a malicious URI.
Example URIs and example exploit code have been provided:
Solution / Fix
PHP ICalendar Multiple Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any solutions for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any solutions for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
PHP ICalendar Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- PHP iCalendar Homepage (PHP iCalendar)