vendor:
EventCalendar PHP
by:
SecurityFocus
7,5
CVSS
HIGH
Multiple Input Validation Vulnerabilities
20
CWE
Product Name: EventCalendar PHP
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: YES
Related CWE: N/A
CPE: a:eventcalendar:event_calendar_php
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Event Calender PHP Multiple Input Validation Vulnerabilities
Event Calender PHP is prone to multiple input validation vulnerabilities. Exploiting these vulnerabilities could allow an attacker to execute arbitrary script code, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Event Calender PHP 1.2 is vulnerable; other versions may also be affected.
Mitigation:
Input validation should be performed to ensure that untrusted data is not used to execute unintended commands.