Vulnerabilities > CVE-2006-1336 - Cross-Site Scripting vulnerability in Extcalendar 1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) year, (2) month, (3) next, and (4) prev parameters. This issue is reportedly addressed in ExtCalendar 2.0. Symantec has not confirmed this fix. Affected users are advised to contact the vendor for further information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | ExtCalendar 1.0 Cross-Site Scripting Vulnerabilities. CVE-2006-1336. Webapps exploit for php platform |
id | EDB-ID:27443 |
last seen | 2016-02-03 |
modified | 2006-03-18 |
published | 2006-03-18 |
reporter | Soothackers |
source | https://www.exploit-db.com/download/27443/ |
title | ExtCalendar 1.0 - Cross-Site Scripting Vulnerabilities |
References
- http://secunia.com/advisories/19321
- http://securityreason.com/securityalert/601
- http://www.osvdb.org/23969
- http://www.securityfocus.com/archive/1/428131/100/0/threaded
- http://www.securityfocus.com/bid/17146
- http://www.vupen.com/english/advisories/2006/1012
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25350