|
|
| |
|
| |
WebCalendar: multiple vulnerabilities
| Package(s): | WebCalendar |
CVE #(s): | |
| Created: | August 5, 2013 |
Updated: | August 7, 2013 |
| Description: |
From the WebCalendar bug report:
Version 1.2.7 (22 Jan 2013)
- Security fix: Do not show the reason for a failed login (i.e. "no such user")
- Security fix: Escape HTML characters in category name.
- Security fix: Check all passed in fields (either via HTML form or via URL parameter) for certain malicious tags (script, embed, etc.) and generate fatal error if found.
|
| Alerts: |
|
( Log in to post comments)
|
|
|