CVE-2010-2041
25.05.2010, 14:30
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction parameters.
Vendor | Product | Version |
---|---|---|
php-calendar | php-calendar | 𝑥 ≤ 2.0 |
php-calendar | php-calendar | 0.1 |
php-calendar | php-calendar | 0.2 |
php-calendar | php-calendar | 0.3 |
php-calendar | php-calendar | 0.4 |
php-calendar | php-calendar | 0.5 |
php-calendar | php-calendar | 0.6 |
php-calendar | php-calendar | 0.7 |
php-calendar | php-calendar | 0.8 |
php-calendar | php-calendar | 0.9 |
php-calendar | php-calendar | 0.9.1 |
php-calendar | php-calendar | 0.10 |
php-calendar | php-calendar | 1.1 |
php-calendar | php-calendar | 2.0:beta1 |
php-calendar | php-calendar | 2.0:beta2 |
php-calendar | php-calendar | 2.0:beta3 |
php-calendar | php-calendar | 2.0:beta4 |
php-calendar | php-calendar | 2.0:beta5 |
𝑥
= Vulnerable software versions
References