CVE-2010-0376
EUVD-2010-040721.01.2010, 22:30
Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: this issue is reportedly resultant from a forced SQL error message that occurs from exploitation of CVE-2010-0375.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jce-tech | php_calendars_script | * |
𝑥
= Vulnerable software versions
References