PublicDate: 2006-12-20 23:28:00 UTC Candidate: CVE-2006-6669 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6669 Description: Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_webcalendar: ignored (reached end-of-life) edgy_webcalendar: needed (reached end-of-life) feisty_webcalendar: DNE gutsy_webcalendar: released (1.0.5-12) hardy_webcalendar: released (1.0.5-12) intrepid_webcalendar: released (1.0.5-12) jaunty_webcalendar: released (1.0.5-12) karmic_webcalendar: released (1.0.5-12) devel_webcalendar: released (1.0.5-12) upstream_webcalendar: needs-triage