Vulnerabilities > CVE-2007-3182 - Cross-Site Scripting vulnerability in Vincent HOR Calendarix 0.7.20070307

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
vincent-hor
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.

Vulnerable Configurations

Part Description Count
Application
Vincent_Hor
1

Exploit-Db

descriptionCalendarix 0.7.20070307 Multiple Cross-Site Scripting Vulnerabilities. CVE-2007-3182. Webapps exploit for php platform
idEDB-ID:30232
last seen2016-02-03
modified2007-06-25
published2007-06-25
reporterJesper Jurcenoks
sourcehttps://www.exploit-db.com/download/30232/
titleCalendarix 0.7.20070307 - Multiple Cross-Site Scripting Vulnerabilities