| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.17613 |
| Category: | Web application abuses |
| Title: | Topic Calendar XSS |
| Summary: | Checks for the presence of a Topic Calendar XSS |
| Description: | Synopsis : The remote web server contains a PHP script which is vulnerable to a cross site scripting issue. Description : The remote host is running Topic Calendar, a module for phpBB which adds calendaring support to phpBB. Due to improper filtering done by the script 'calendar_scheduler.php' a remote attacker can cause the Topic Calendar product to include arbitrary HTML and/or JavaScript. Solution : Disable this module or upgrade to a newer version |
| Cross-Ref: |
BugTraq ID: 12893 Common Vulnerability Exposure (CVE) ID: CVE-2005-0872 Bugtraq: 20050324 Multiple vulnerabilities in Topic Calendar 1.0.1 for phpBB (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=111168190630576&w=2 http://securitytracker.com/id?1013554 http://secunia.com/advisories/14659 XForce ISS Database: topic-calendar-start-xss(19821) http://xforce.iss.net/xforce/xfdb/19821 |
| Copyright | This script is Copyright (C) 2005 Noam Rathaus |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|