{
    "id": "CVE-2007-1111",
    "published": "2007-02-26 17:28:00",
    "last_modified": "2026-06-16 22:36:58",
    "cvss_score": "6.8",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "cwe": null,
    "description": "Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.",
    "epss_score": "0.06091",
    "epss_percentile": "0.93191",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-30 18:17:06",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "activecalendar",
            "product": "activecalendar"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "29646",
            "title": "Active Calendar 1.2 - '/data/flatevents.php?css' Cross-Site Scripting",
            "date": "2007-02-24",
            "url": "https://www.exploit-db.com/exploits/29646"
        },
        {
            "source": "exploit-db",
            "ref_id": "29647",
            "title": "Active Calendar 1.2 - '/data/js.php?css' Cross-Site Scripting",
            "date": "2007-02-24",
            "url": "https://www.exploit-db.com/exploits/29647"
        },
        {
            "source": "exploit-db",
            "ref_id": "29648",
            "title": "Active Calendar 1.2 - '/data/m_2.php?css' Cross-Site Scripting",
            "date": "2007-02-24",
            "url": "https://www.exploit-db.com/exploits/29648"
        },
        {
            "source": "exploit-db",
            "ref_id": "29649",
            "title": "Active Calendar 1.2 - '/data/m_3.php?css' Cross-Site Scripting",
            "date": "2007-02-24",
            "url": "https://www.exploit-db.com/exploits/29649"
        },
        {
            "source": "exploit-db",
            "ref_id": "29650",
            "title": "Active Calendar 1.2 - '/data/m_4.php?css' Cross-Site Scripting",
            "date": "2007-02-24",
            "url": "https://www.exploit-db.com/exploits/29650"
        },
        {
            "source": "exploit-db",
            "ref_id": "29651",
            "title": "Active Calendar 1.2 - '/data/y_2.php?css' Cross-Site Scripting",
            "date": "2007-02-24",
            "url": "https://www.exploit-db.com/exploits/29651"
        },
        {
            "source": "exploit-db",
            "ref_id": "29652",
            "title": "Active Calendar 1.2 - '/data/y_3.php?css' Cross-Site Scripting",
            "date": "2007-02-24",
            "url": "https://www.exploit-db.com/exploits/29652"
        },
        {
            "source": "exploit-db",
            "ref_id": "29653",
            "title": "Active Calendar 1.2 - '/data/mysqlevents.php?css' Cross-Site Scripting",
            "date": "2007-02-24",
            "url": "https://www.exploit-db.com/exploits/29653"
        }
    ],
    "refs_list": [
        "http://securityreason.com/securityalert/2299",
        "http://www.osvdb.org/33145",
        "http://www.osvdb.org/33146",
        "http://www.osvdb.org/33147",
        "http://www.osvdb.org/33148",
        "http://www.osvdb.org/33149",
        "http://www.osvdb.org/33150",
        "http://www.osvdb.org/33151",
        "http://www.osvdb.org/33152",
        "http://www.osvdb.org/33153",
        "http://www.securityfocus.com/archive/1/461146/100/0/threaded",
        "http://www.securityfocus.com/archive/1/461313/100/0/threaded",
        "http://www.securityfocus.com/bid/22705",
        "http://www.vupen.com/english/advisories/2007/0759",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/32690",
        "http://securityreason.com/securityalert/2299",
        "http://www.osvdb.org/33145",
        "http://www.osvdb.org/33146",
        "http://www.osvdb.org/33147",
        "http://www.osvdb.org/33148",
        "http://www.osvdb.org/33149",
        "http://www.osvdb.org/33150",
        "http://www.osvdb.org/33151",
        "http://www.osvdb.org/33152",
        "http://www.osvdb.org/33153"
    ]
}