5

CVE-2005-3982

CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WebcalendarWebcalendar Version1.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.08% 0.934
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19240
Patch
Vendor Advisory
http://www.debian.org/security/2006/dsa-1002
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/418286/100/0/threaded
http://secunia.com/advisories/17848
Patch
Vendor Advisory
http://vd.lwang.org/webcalendar_multiple_vulns.txt
http://www.osvdb.org/21383
http://www.securityfocus.com/bid/15673
http://www.vupen.com/english/advisories/2005/2702