CVE-2010-2041

Php-calendar < 2.0 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction parameters.

Scores

EPSS 0.0052
EPSS Percentile 66.3%

Classification

CWE
CWE-79
Status published

Affected Products (19)

php-calendar/php-calendar < 2.0
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
php-calendar/php-calendar
... and 4 more

Timeline

Published May 25, 2010
Tracked Since Feb 18, 2026