CVE-2013-5953
N/A
N/A
Summary
Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) calid or (2) paletteDefault parameter in an editevent action to index.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://packetstormsecurity.com/files/125738
- http://secunia.com/advisories/57360
- http://archives.neohapsis.com/archives/fulldisclosure/2014-03/0276.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91820
References
- http://packetstormsecurity.com/files/125738
- http://secunia.com/advisories/57360
- http://archives.neohapsis.com/archives/fulldisclosure/2014-03/0276.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91820
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.