|
Family: CGI abuses --> Category: infos
Calendar Express Multiple Flaws Vulnerability Scan
Vulnerability Scan Summary Checks Calendar Express XSS and SQL flaws
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script which is vulnerable to a cross
site scripting and SQL injection vulnerability.
Description :
The remote host is using Calendar Express, a PHP web calendar.
A vulnerability exists in this version which may allow a possible hacker to
execute arbitrary HTML and script code in the context of the user's browser,
and SQL injection.
A possible hacker may exploit these flaws to use the remote host to perform attacks
against third-party users, or to execute arbitrary SQL statements on the remote
SQL database.
Solution :
Upgrade to the latest version of this software.
Threat Level:
Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|