Cross-Site Scripting Vulnerabilities in Sun ONE Calendar Server
CVE-2009-1218
Currently unrated
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 1 April 2009
Summary
The Sun Calendar Express Web Server contains multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML. This is achievable through improper input handling in parameters such as 'fmt-out' in login.wcap and 'date' in command.shtml. Successful exploitation could lead to unauthorized access or the execution of malicious scripts within a victim's browser session.
References
Timeline
Vulnerability published
Vulnerability Reserved