|
BosDates contains a flaw that allows a remote cross site scripting attack. Input passed to the "type" parameter in calendar.php and to the "category" parameter in calendar_search.php is not properly sanitised before being returned to the user. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|