CVE-2008-7018 Information

Description

Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an add action in index.php.

Reference

http://www.securityfocus.com/archive/1/496796 http://www.securityfocus.com/bid/31478 https://exchange.xforce.ibmcloud.com/vulnerabilities/45517

Share on: