HIO-2010-0114 WebCalendar Multiple Vulnerabilities PDF Print E-mail

WebCalendar 1.2b0 and earlier contains multiple flaws that allow cross-site scripting and cross-site request forgery.

1) XSS: Input passed via various parameters to multiple scripts is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

2) CSRF: The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. delete an event or ban an IP address from posting, when a logged-in administrative user visits a malicious web page.

References:

CVE-2010-0636 , 0637, 0638

BID: 38053

FrSIRT: N/A

Nessus:N/A

OSVDB: 62095, 62096, 62097, 62098, 62099

SA: 38222  

XF: 

Related: 

Vendor Solution:


 
< Prev   Next >