Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-02-21T23:00:00

Updated: 2018-10-16T14:57:01

Reserved: 2007-02-21T00:00:00


Link: CVE-2007-1050

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2007-02-21T23:28:00.000

Modified: 2018-10-16T16:36:29.470


Link: CVE-2007-1050

JSON object: View

cve-icon Redhat Information

No data.

CWE