vendor:
PHP Event Calendar
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting (XSS), HTML Injection, Directory Traversal, Cross-Site Request Forgery (CSRF)
79
CWE
Product Name: PHP Event Calendar
Affected Version From: 1.5
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:softcomplex:php_event_calendar:1.5
Platforms Tested:
Unknown
SoftComplex PHP Event Calendar Remote Security Vulnerabilities
Attackers can exploit these issues to obtain sensitive information, upload arbitrary files, execute arbitrary script code, steal cookie-based authentication credentials, and perform certain administrative actions.
Mitigation:
Update to a patched version of PHP Event Calendar. Avoid using user-supplied input to construct SQL queries or dynamically execute code.