CVE-2010-2041

Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction parameters.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
php-calendarphp-calendar
𝑥
≤ 2.0
php-calendarphp-calendar
0.1
php-calendarphp-calendar
0.2
php-calendarphp-calendar
0.3
php-calendarphp-calendar
0.4
php-calendarphp-calendar
0.5
php-calendarphp-calendar
0.6
php-calendarphp-calendar
0.7
php-calendarphp-calendar
0.8
php-calendarphp-calendar
0.9
php-calendarphp-calendar
0.9.1
php-calendarphp-calendar
0.10
php-calendarphp-calendar
1.1
php-calendarphp-calendar
2.0:beta1
php-calendarphp-calendar
2.0:beta2
php-calendarphp-calendar
2.0:beta3
php-calendarphp-calendar
2.0:beta4
php-calendarphp-calendar
2.0:beta5
𝑥
= Vulnerable software versions