Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
K5N WebCalendar多个跨站脚本攻击漏洞
Vulnerability Description
WebCalendar是一款基于Web的日历应用程序。该应用程序具备查看日历、添加提醒、制作时间表等功能。 WebCalendar存在多个跨站脚本攻击漏洞。远程攻击者可以借助多个参数执行跨站脚本攻击,导致任意web脚本或HTML注入。这些参数包括:(1) 脚本users.php的tab 参数,脚本(2) day.php,(3) month.php以及(4) week.php的PATH_INFO参数。 注意:该漏洞的详细来源于第三方。
CVSS Information
N/A
Vulnerability Type
N/A