CVE-2008-7018
Nashtech Easy Php Calendar - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an add action in index.php.
Scores
EPSS
0.0025
EPSS Percentile
48.5%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
nashtech/easy_php_calendar
n/a/n/a
Timeline
Published
Aug 21, 2009
Tracked Since
Feb 18, 2026