BreakCalendar < 1.3 XSS

medium Nessus Plugin ID 14225

Synopsis

The remote web server contains a CGI that is affected by a cross-site scripting vulnerability.

Description

The remote host seems to be running BreakCalendar, a web-based calendar.

The remote version of this software is vulnerable to a cross-site scripting attack that may allow an attacker to use the remote host to perform attacks against third-party users.

Solution

Upgrade to version 1.3.

Plugin Details

Severity: Medium

ID: 14225

File Name: breakcal_xss.nasl

Version: 1.29

Type: remote

Published: 8/9/2004

Updated: 1/19/2021

Supported Sensors: Nessus

Vulnerability Information

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Available: true

Exploit Ease: No exploit is required

Vulnerability Publication Date: 7/1/2004

Reference Information

BID: 10847

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990