Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information. Lucid Designs, Lucid Calendar, 0.22 is unsupported. A new, supported version of this product will be released in the near future.
Publication date: Thu, 15 Jun 2006 15:02:00 +0000