CaLogic new event cross-site scripting

calogic-newevent-xss (24077) The risk level is classified as MediumMedium Risk

Description:

CaLogic is vulnerable to cross-site scripting, caused by improper validation of user-supplied input when adding a new event to the calendar. A remote attacker could exploit this vulnerability using the title field to execute script in a victim¿s Web browser within the security context of the hosting Web site, allowing the attacker to steal the victim¿s cookie-based authentication credentials.

Platforms Affected:

  • CaLogic, CaLogic 1.2.2
  • Compaq, Tru64 4.0

Remedy:

No remedy available as of July 4, 2009.

Consequences:

Gain Access

References:

  • CaLogic Web page, Welcome To the Official CaLogic Support Website! at http://www.calogic.de/.
  • eVuln Advisory EV0024, CaLogic Calendars Multiple XSS Vulnerabilities at http://www.evuln.com/vulns/24/summary.html.
  • BID-16206: CaLogic Calendars Add Event Multiple HTML Injection Vulnerabilities
  • CVE-2006-0180: Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the Adding New Event page, and possibly other vectors, involving iframe tags.
  • OSVDB ID: 22322: CaLogic New Event title Field XSS
  • SA18417: CaLogic "title" New Event Script Insertion Vulnerability
  • VUPEN/ADV-2006-0149: CaLogic New Event title Field Cross Site Scripting Vulnerability

Reported:

Jan 11, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page