Vulnerabilities > CVE-2006-0657 - HTML Injection vulnerability in Softcomplex PHP Event Calendar 1.5

047910
CVSS 3.5 - LOW
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
softcomplex

Summary

Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php. NOTE: while this issue was originally reported as XSS, the primary issue might be direct static code injection with resultant XSS.

Vulnerable Configurations

Part Description Count
Application
Softcomplex
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/43944/EV0063.txt
idPACKETSTORM:43944
last seen2016-12-05
published2006-02-17
reporterAliaksandr Hartsuyeu
sourcehttps://packetstormsecurity.com/files/43944/EV0063.txt.html
titleEV0063.txt