CVE-2008-5061
Mini Web Calendar 1.2 - Cross-Site Scripting via URL Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5061. PoCs published by ahmadbady.
AI-analyzed exploit summary The exploit demonstrates two vulnerabilities in Mini Web Calendar 1.2: a local file inclusion (LFI) via `cal_pdf.php` and a reflected XSS via `cal_default.php`. Both are trivial to execute and require no authentication.
Description
Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL.
Exploits (1)
The exploit demonstrates two vulnerabilities in Mini Web Calendar 1.2: a local file inclusion (LFI) via `cal_pdf.php` and a reflected XSS via `cal_default.php`. Both are trivial to execute and require no authentication.