CVE-2007-1050 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 5.1% (pctl 92)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 5.09% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-02-21 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| abledesign | mycalendar |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | AbleDesign MyCalendar 2.20.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities | 2007-02-20 |
References
- http://forums.avenir-geopolitique.net/viewtopic.php?t=2686
- http://osvdb.org/33317
- http://osvdb.org/33318
- http://osvdb.org/33319
- http://secunia.com/advisories/24222
- http://securityreason.com/securityalert/2270
- http://www.securityfocus.com/archive/1/460598/100/0/threaded
- http://www.securityfocus.com/bid/22635
- http://www.vupen.com/english/advisories/2007/0679
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32581
- http://forums.avenir-geopolitique.net/viewtopic.php?t=2686
- http://osvdb.org/33317
- http://osvdb.org/33318
- http://osvdb.org/33319
- http://secunia.com/advisories/24222
- http://securityreason.com/securityalert/2270
- http://www.securityfocus.com/archive/1/460598/100/0/threaded
- http://www.securityfocus.com/bid/22635
- http://www.vupen.com/english/advisories/2007/0679
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32581
→ the Explorer · watch your stack · NVD