Description
|
|
Two vulnerabilities have been identified in Mini Web Calendar, which could be exploited by attackers to gain knowledge of sensitive information.
The first issue is caused by an input validation error in the "php/cal_pdf.php" when processing the "thefile" parameter, which could be exploited to download arbitrary files from a vulnerable web server.
The second vulnerability is caused by an input validation error in the "php/cal_default.php" script when handling user-supplied URLs, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected site.
|