VYPR
Unrated severityNVD Advisory· Published Jan 15, 2010· Updated Apr 23, 2026

CVE-2010-0349

CVE-2010-0349

Description

Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable.

Affected products

3
  • cpe:2.3:a:c-3.co.jp:webcalenderc3:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:c-3.co.jp:webcalenderc3:*:*:*:*:*:*:*:*range: <=0.32
    • cpe:2.3:a:c-3.co.jp:webcalenderc3:0.31:*:*:*:*:*:*:*
    • cpe:2.3:a:c-3.co.jp:webcalenderc3:0.31:s2:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.