Vulnerabilities > Softcomplex > PHP Event Calendar > 1.5

DATE CVE VULNERABILITY TITLE RISK
2006-02-13 CVE-2006-0657 HTML Injection vulnerability in Softcomplex PHP Event Calendar 1.5
Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php.
network
softcomplex
3.5