Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2008-1954 SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user… Web Calendar Pro after 4.1 Fix from $1,9502008-04-25 HIGH 7.5 CVE-2007-1343 includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote … Webcalendar Patch available Fix from $1,9502007-03-08 MEDIUM 6.8 CVE-2006-6669 Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web scrip… Webcalendar Mitigation only Fix from $1,6002006-12-20 MEDIUM 6.4 CVE-2006-2762 PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL i… Webcalendar Mitigation only Fix from $1,6002006-06-02 MEDIUM 5.0 CVE-2006-2247 WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enume… Webcalendar Mitigation only Fix from $1,6002006-05-09 MEDIUM 5.0 CVE-2006-1537 Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests… Webcalendar Mitigation only Fix from $1,6002006-03-30 HIGH 7.5 CVE-2005-3984 SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_repor… Webcalendar Patch available Fix from $1,9502005-12-04 MEDIUM 5.0 CVE-2005-3982EPSS 7% CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response … Webcalendar Patch available Fix from $1,6002005-12-04 HIGH 7.5 CVE-2005-3949 Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to… Webcalendar Mitigation only Fix from $1,9502005-12-01 MEDIUM 5.0 CVE-2005-3961 export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter. Webcalendar Mitigation only Fix from $1,6002005-12-01 HIGH 7.5 CVE-2005-2717 PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, … Webcalendar Patch available Fix from $1,9502005-08-29 HIGH 7.5 CVE-2005-2320 WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges. Webcalendar Patch available Fix from $1,9502005-07-19 MEDIUM 6.4 CVE-2005-0474 SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL comma… Webcalendar Patch available Fix from $1,6002005-03-30 HIGH 7.5 CVE-2004-1508 init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter. Webcalendar Mitigation only Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-1507 CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform H… Webcalendar No fix yet Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2002-2065 WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extens… Webcalendar Patch available Fix from $1,6002002-12-31 HIGH 7.5 CVE-2001-0477 Vulnerability in WebCalendar 0.9.26 allows remote command execution. Webcalendar Patch available Fix from $1,9502001-06-27