Vulnerabilities > CVE-2007-1111 - Unspecified vulnerability in Activecalendar 1.2.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN activecalendar
exploit available
Summary
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Active Calendar 1.2 data/m_3.php css Parameter XSS. CVE-2007-1111. Webapps exploit for php platform id EDB-ID:29649 last seen 2016-02-03 modified 2007-02-24 published 2007-02-24 reporter Simon Bonnard source https://www.exploit-db.com/download/29649/ title Active Calendar 1.2 data/m_3.php css Parameter XSS description Active Calendar 1.2 data/m_4.php css Parameter XSS. CVE-2007-1111. Webapps exploit for php platform id EDB-ID:29650 last seen 2016-02-03 modified 2007-02-24 published 2007-02-24 reporter Simon Bonnard source https://www.exploit-db.com/download/29650/ title Active Calendar 1.2 data/m_4.php css Parameter XSS description Active Calendar 1.2 data/flatevents.php css Parameter XSS. CVE-2007-1111. Webapps exploit for php platform id EDB-ID:29646 last seen 2016-02-03 modified 2007-02-24 published 2007-02-24 reporter Simon Bonnard source https://www.exploit-db.com/download/29646/ title Active Calendar 1.2 data/flatevents.php css Parameter XSS description Active Calendar 1.2 data/y_2.php css Parameter XSS. CVE-2007-1111. Webapps exploit for php platform id EDB-ID:29651 last seen 2016-02-03 modified 2007-02-24 published 2007-02-24 reporter Simon Bonnard source https://www.exploit-db.com/download/29651/ title Active Calendar 1.2 data/y_2.php css Parameter XSS description Active Calendar 1.2 data/y_3.php css Parameter XSS. CVE-2007-1111 . Webapps exploit for php platform id EDB-ID:29652 last seen 2016-02-03 modified 2007-02-24 published 2007-02-24 reporter Simon Bonnard source https://www.exploit-db.com/download/29652/ title Active Calendar 1.2 data/y_3.php css Parameter XSS description Active Calendar 1.2 data/m_2.php css Parameter XSS. CVE-2007-1111. Webapps exploit for php platform id EDB-ID:29648 last seen 2016-02-03 modified 2007-02-24 published 2007-02-24 reporter Simon Bonnard source https://www.exploit-db.com/download/29648/ title Active Calendar 1.2 data/m_2.php css Parameter XSS description Active Calendar 1.2 data/mysqlevents.php css Parameter XSS. CVE-2007-1111. Webapps exploit for php platform id EDB-ID:29653 last seen 2016-02-03 modified 2007-02-24 published 2007-02-24 reporter Simon Bonnard source https://www.exploit-db.com/download/29653/ title Active Calendar 1.2 data/mysqlevents.php css Parameter XSS description Active Calendar 1.2 data/js.php css Parameter XSS. CVE-2007-1111. Webapps exploit for php platform id EDB-ID:29647 last seen 2016-02-03 modified 2007-02-24 published 2007-02-24 reporter Simon Bonnard source https://www.exploit-db.com/download/29647/ title Active Calendar 1.2 data/js.php css Parameter XSS
References
- http://securityreason.com/securityalert/2299
- http://securityreason.com/securityalert/2299
- http://www.osvdb.org/33145
- http://www.osvdb.org/33145
- http://www.osvdb.org/33146
- http://www.osvdb.org/33146
- http://www.osvdb.org/33147
- http://www.osvdb.org/33147
- http://www.osvdb.org/33148
- http://www.osvdb.org/33148
- http://www.osvdb.org/33149
- http://www.osvdb.org/33149
- http://www.osvdb.org/33150
- http://www.osvdb.org/33150
- http://www.osvdb.org/33151
- http://www.osvdb.org/33151
- http://www.osvdb.org/33152
- http://www.osvdb.org/33152
- http://www.osvdb.org/33153
- http://www.osvdb.org/33153
- http://www.securityfocus.com/archive/1/461146/100/0/threaded
- http://www.securityfocus.com/archive/1/461146/100/0/threaded
- http://www.securityfocus.com/archive/1/461313/100/0/threaded
- http://www.securityfocus.com/archive/1/461313/100/0/threaded
- http://www.securityfocus.com/bid/22705
- http://www.securityfocus.com/bid/22705
- http://www.vupen.com/english/advisories/2007/0759
- http://www.vupen.com/english/advisories/2007/0759
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32690
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32690