CVE Vulnerabilities

CVE-2006-6669

Published: Dec 20, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter.

Affected Software

Name Vendor Start Version End Version
Webcalendar Webcalendar 1.0.4 (including) 1.0.4 (including)
Webcalendar Ubuntu dapper *
Webcalendar Ubuntu devel *
Webcalendar Ubuntu edgy *
Webcalendar Ubuntu gutsy *
Webcalendar Ubuntu hardy *
Webcalendar Ubuntu intrepid *
Webcalendar Ubuntu jaunty *
Webcalendar Ubuntu karmic *

References