Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
References 8 Total
- http://www.egroupware.org/epl-changelog
- http://packetstormsecurity.org/files/100180/eGroupware-1.8.001-Cross-Site-Scripting.html
- http://www.egroupware.org/changelog
- securityfocus.com: 52770 vdb-entry
- http://www.autosectools.com/Advisory/eGroupware-1.8.001-Reflected-Cross-site-Scripting-178
- comments.gmane.org: [egroupware-german] 20110805 new EGroupware SECURITY & maintenance release 1.8.001.20110805 mailing-list
- openwall.com: [oss-security] 20120328 Re: CVE request: egroupware before 1.8.002 various security issues mailing-list
- openwall.com: [oss-security] 20120329 Re: CVE request: egroupware before 1.8.002 various security issues mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 8 Total
- http://www.egroupware.org/epl-changelog x_transferred
- http://packetstormsecurity.org/files/100180/eGroupware-1.8.001-Cross-Site-Scripting.html x_transferred
- http://www.egroupware.org/changelog x_transferred
- securityfocus.com: 52770 vdb-entryx_transferred
- http://www.autosectools.com/Advisory/eGroupware-1.8.001-Reflected-Cross-site-Scripting-178 x_transferred
- comments.gmane.org: [egroupware-german] 20110805 new EGroupware SECURITY & maintenance release 1.8.001.20110805 mailing-listx_transferred
- openwall.com: [oss-security] 20120328 Re: CVE request: egroupware before 1.8.002 various security issues mailing-listx_transferred
- openwall.com: [oss-security] 20120329 Re: CVE request: egroupware before 1.8.002 various security issues mailing-listx_transferred