Record summary

CVE-2007-1050 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAbleDesign MyCalendar 2.20.3 - 'index.php' Multiple Cross-Site Scripting VulnerabilitiesExploitDB exploitby sn0oPyNot analyzed1 file
ExploitDB

PoC details

References

11