Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.osvdb.org/61629 | vdb entry |
http://webcal.c-3.jp/zeijakusei.html | vendor advisory |
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000002.html | third party advisory |
http://secunia.com/advisories/38135 | third party advisory vendor advisory |
http://jvn.jp/en/jp/JVN33977065/index.html | third party advisory |