CVE-2007-6274: XSS
Multiple cross-site scripting (XSS) vulnerabilities in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) day or (2) year parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6274?
CVE-2007-6274 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2007-6274?
To fix CVE-2007-6274, users should update to a version of Bcoos newer than 1.0.10 where this vulnerability has been patched.
What are the impacts of exploiting CVE-2007-6274?
Exploiting CVE-2007-6274 allows attackers to inject malicious web scripts or HTML, potentially leading to data theft or session hijacking.
Which software versions are affected by CVE-2007-6274?
CVE-2007-6274 affects Bcoos version 1.0.10 and earlier.
Can CVE-2007-6274 be exploited remotely?
Yes, CVE-2007-6274 can be exploited remotely by attackers who can manipulate the day or year parameters in the Event Calendar.