CVE-2005-2717
- EPSS 1.5%
- Veröffentlicht 29.08.2005 20:14:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts.
CVE-2005-2320
- EPSS 0.75%
- Veröffentlicht 19.07.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.
CVE-2005-0474
- EPSS 0.56%
- Veröffentlicht 30.03.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.
CVE-2004-1508
- EPSS 0.87%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
- EPSS 0.41%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.
CVE-2004-1506
- EPSS 0.41%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated usi...
- EPSS 0.35%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root.
CVE-2001-0477
- EPSS 1.79%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Vulnerability in WebCalendar 0.9.26 allows remote command execution.