Cross-Site Scripting Vulnerabilities in Sun ONE Calendar Server
CVE-2009-1218

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
1 April 2009

Summary

The Sun Calendar Express Web Server contains multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML. This is achievable through improper input handling in parameters such as 'fmt-out' in login.wcap and 'date' in command.shtml. Successful exploitation could lead to unauthorized access or the execution of malicious scripts within a victim's browser session.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.