Availability Booking Calendar PHP是GZ Scripts开源的一个可用性预订日历系统。 Availability Booking Calendar PHP 5.0版本存在跨站脚本漏洞,该漏洞源于文件/index.php的参数session_id会导致跨站脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHP Jabbers | Availability Booking Calendar | 5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4110.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-4111 | 4.3 MEDIUM | PHP Jabbers Bus Reservation System index.php cross site scripting |
| CVE-2023-4117 | 4.3 MEDIUM | PHP Jabbers Rental Property Booking index.php cross site scripting |
| CVE-2023-4116 | 4.3 MEDIUM | PHP Jabbers Taxi Booking index.php cross site scripting |
| CVE-2023-4115 | 4.3 MEDIUM | PHP Jabbers Cleaning Business index.php cross site scripting |
| CVE-2023-4114 | 4.3 MEDIUM | PHP Jabbers Night Club Booking Software index.php cross site scripting |
| CVE-2023-4113 | 4.3 MEDIUM | PHP Jabbers Service Booking Script index.php cross site scripting |
| CVE-2023-4112 | 4.3 MEDIUM | PHP Jabbers Shuttle Booking Software index.php cross site scripting |
No comments yet