Unrated severityNVD Advisory· Published Apr 12, 2005· Updated Apr 16, 2026
CVE-2005-1146
CVE-2005-1146
Description
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145
Affected products
1- cpe:2.3:a:calendarscript:calendarscript:3.20:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- securitytracker.com/idnvdVendor Advisory
- www.snkenjoi.com/secadv/secadv3.txtnvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/20103nvd
News mentions
0No linked articles in our index yet.