Vulnerabilities > CVE-2004-1506 - Unspecified vulnerability in Webcalendar
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags.
Vulnerable Configurations
References
- http://marc.info/?l=bugtraq&m=110011618724455&w=2
- http://marc.info/?l=bugtraq&m=110011618724455&w=2
- http://secunia.com/advisories/13164
- http://secunia.com/advisories/13164
- http://www.securityfocus.com/bid/11651
- http://www.securityfocus.com/bid/11651
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18026
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18026