Record summary

CVE-2009-1218 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the fmt-out parameter to login.wcap or (2) the date parameter to command.shtml.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSun Java System Calendar Server 6 - 'command.shtml' Cross-Site ScriptingExploitDB exploitby SCS teamNot analyzed1 file
ExploitDB

PoC details

References

8