PHP-Nuke Event Calendar contains a flaw that will allow an attacker to inject arbitrary script. The problem is that the field "event comment" does not suffiiciently sanitize variable, which will allow an attacker to inject arbitrary javascript code.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
OSVDB:
Web Related
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.