CVE-2008-1345
MyioSoft EasyCalendar <= 4.0tr - Cross-Site Scripting via Day Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1345. PoCs published by JosS.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in EasyCalendar <= 4.0tr, including SQL injection, blind SQL injection, and XSS. The PoC provides specific URLs and payloads to exploit these vulnerabilities.
Description
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and earlier allows remote attackers to inject arbitrary web script or HTML via the day parameter in a dayview action.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in EasyCalendar <= 4.0tr, including SQL injection, blind SQL injection, and XSS. The PoC provides specific URLs and payloads to exploit these vulnerabilities.