| CVE-2022-4455 |
|
Low |
Dec 13, 2022 |
A vulnerability, which was classified as problematic, was found in sproctor php-calendar. This affects an unknown part of the file index.php. The manip
more...
A vulnerability, which was classified as problematic, was found in sproctor php-calendar. This affects an unknown part of the file index.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is a2941109b42201c19733127ced763e270a357809. It is recommended to apply a patch to fix this issue. The identifier VDB-215445 was assigned to this vulnerability.
less...
|
2.0.5, 2.0.1, 1.1, 1.0, 0.10.9, 0.10.8, 0.10.7, 0.10.6, 0.10.5, 0.10.4
|
| CVE-2017-6485 |
|
Medium |
Mar 05, 2017 |
A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-su
more...
A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed to the "php-calendar-master/error.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
less...
|
2.0.5, 2.0.1, 1.1, 1.0, 0.10.9, 0.10.8, 0.10.7, 0.10.6, 0.10.5, 0.10.4
|