Menu

#7 XSS Vulnerability

open
nobody
security (2)
8
2007-06-29
2007-06-29
Jay E
No

Cross-site scripting vulnerability via several parameters. Vulnerability does not affect affect any authentication (such as web-based admin) in CGI Calendar proper, but may affect web server provided authentication (such as HTTP Basic) depending on how that authentication is implemented by the web server. Jay has a simple proof-of-concept of the vulnerability for anyone wanting to fix it. I do not have a POC for any kind of authentication vulnerability. All CERT-like orgs that have listed this bug have listed it as low risk.

http://xforce.iss.net/xforce/xfdb/24946

Discussion


Log in to post a comment.

MongoDB Logo MongoDB