Advisory: Multiple Cross-Site Scripting vulnerabilities in WebCalendar Advisory ID: SSCHADV2011-008 Author: Stefan Schurtz Affected Software: Version 1.2.3 and probably prior versions Vendor URL: http://www.k5n.us/webcalendar.php Vendor Status: informed CVE-ID: - ========================== Vulnerability Description: ========================== This is a Cross-Site Scripting vulnerability ================== Technical Details: ================== http://[target]/webapps/webcalendar/about/"> http://[target]/webapps/webcalendar/about/"> http://[target]/webapps/webcalendar/colors.php?color=">