First published: Wed Mar 04 2009(Updated: )
Cross-site scripting (XSS) vulnerability in piCal 0.91h and earlier, a module for XOOPS, allows remote attackers to inject arbitrary web script or HTML via the event_id parameter in index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mihai Bazon Pical | <=0.91h | |
Xoops Xm Memberstats |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0805 has a moderate severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2009-0805, upgrade the piCal module to version 0.91i or later where the vulnerability is patched.
CVE-2009-0805 affects piCal versions 0.91h and earlier, which is a module for the XOOPS content management system.
Yes, CVE-2009-0805 can lead to data theft as attackers can inject malicious scripts that may capture sensitive user information.
The usage of piCal varies, but any installations of version 0.91h or earlier are vulnerable to CVE-2009-0805 and should be assessed.