Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable.
- http://www.openwall.com/lists/oss-security/2012/02/12/3
- http://www.openwall.com/lists/oss-security/2012/02/13/6
No PoCs found on GitHub currently.