Advisory: PHP Booking Calendar Multiple Cross-Site Scripting Vulnerabilities Advisory ID: SSCHADV2011-029 Author: Stefan Schurtz Affected Software: Successfully tested on PHP Booking Calendar 10e Vendor URL: https://sourceforge.net/projects/bookingcalendar/ Vendor Status: informed CVE-ID: - ========================== Vulnerability Description: ========================== PHP Booking Calendar is prone to multiple Cross-Site scripting vulernabilities ================== Technical Details: ================== http:///booking_calendar/user_login.php?origin='" http:///booking_calendar/user_forgot_passwd.php -> E-mail Address -> '" http:///booking_calendar/user_forgot_username.php -> E-mail Address -> '" http:///booking_calendar/user_register.php -> E-mail Address -> '" http:///booking_calendar/user_register.php -> Last Name -> '" http:///booking_calendar/user_register.php -> First Name -> '" ========= Solution: ========= - ==================== Disclosure Timeline: ==================== 16-Oct-2011 - informed developers 18-Oct-2011 - release date of this security advisory ======== Credits: ======== Vulnerabilities found and advisory written by Stefan Schurtz. =========== References: =========== https://sourceforge.net/projects/bookingcalendar/ http://www.rul3z.de/advisories/SSCHADV2011-029.txt