CVE-2024-22635
- EPSS 0.21%
- Veröffentlicht 25.01.2024 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:56:30
WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.
CVE-2023-0289
- EPSS 0.08%
- Veröffentlicht 13.01.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:54
Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.
CVE-2013-1422
- EPSS 0.32%
- Veröffentlicht 04.02.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 01:49:33
webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
CVE-2012-1495
- EPSS 88.48%
- Veröffentlicht 27.01.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:37:05
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
CVE-2012-1496
- EPSS 0.8%
- Veröffentlicht 27.01.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:37:06
Local file inclusion in WebCalendar before 1.2.5.
CVE-2017-10840
- EPSS 0.22%
- Veröffentlicht 29.08.2017 01:35:13
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-10841
- EPSS 2.18%
- Veröffentlicht 29.08.2017 01:35:13
- Zuletzt bearbeitet 20.04.2025 01:37:25
Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.
CVE-2013-1421
- EPSS 0.25%
- Veröffentlicht 22.04.2014 14:23:31
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.
CVE-2012-5384
- EPSS 0.23%
- Veröffentlicht 11.10.2012 15:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, ...
CVE-2012-5385
- EPSS 1.27%
- Veröffentlicht 11.10.2012 15:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.