Vulnerable Systems:
* PHP-Calendar version 2.0 Beta6 and prior
Immune Systems:
* PHP-Calendar version 2.0 Beta7
These issues are caused by input validation errors when processing the "description" and "lastaction" parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.