Multiple cross-site scripting (XSS) vulnerabilities in Jay Eckles CGI Calendar 2.7 allow remote attackers to inject arbitrary web script or HTML via the year parameter in (1) index.cgi and (2) viewday.cgi.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cgi_calendar | Jay_eckles | 2.7 (including) | 2.7 (including) |