Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) ti, (2) bi, or (3) cbgi parameters.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Php_event_calendar | Softcomplex | * | 1.5.1 (including) |