First published: Fri Dec 07 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) day or (2) year parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bcoos | <=1.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6274 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2007-6274, users should update to a version of Bcoos newer than 1.0.10 where this vulnerability has been patched.
Exploiting CVE-2007-6274 allows attackers to inject malicious web scripts or HTML, potentially leading to data theft or session hijacking.
CVE-2007-6274 affects Bcoos version 1.0.10 and earlier.
Yes, CVE-2007-6274 can be exploited remotely by attackers who can manipulate the day or year parameters in the Event Calendar.