Loading
Generated remediation guidance and an executive summary. No account required.
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.
Use CWE-79, Webcalendar Project vendor hub and Webcalendar product page to widen CVE-2013-1421 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2012-1495, CVE-2012-1496 and CVE-2012-5385 for nearby disclosures in the same product family.