RULE(RULE ID:322299)

Rule General Information
Release Date: 2019-07-04
Rule Name: Active Calendar 1.2 css Parameter XSS Vulnerability (CVE-2007-1111)
Severity:
CVE ID:
Rule Protection Details
Description: Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:22705
http://securityreason.com/securityalert/2299
OSVDB:33151
Solutions
Please contact the software vendor to update the software patch.