CVE-2005-2717
- EPSS 2.02%
- Veröffentlicht 29.08.2005 20:14:00
- Zuletzt bearbeitet 16.06.2026 22:15:32
PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts.
CVE-2005-2320
- EPSS 1.43%
- Veröffentlicht 19.07.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:14:40
WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.
CVE-2005-0474
- EPSS 1.44%
- Veröffentlicht 30.03.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:11:10
SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.
CVE-2004-1508
- EPSS 1.63%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:50
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
- EPSS 1.47%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:50
CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.
CVE-2004-1506
- EPSS 1.28%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:50
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated usi...
- EPSS 1.37%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:00:35
WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root.
CVE-2001-0477
- EPSS 4.04%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:54:22
Vulnerability in WebCalendar 0.9.26 allows remote command execution.