Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postcalendar | Postnuke_software_foundation | 3.0 (including) | 3.0 (including) |