Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2008-1954
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user…
Web Calendar Pro
after 4.1
HIGH 7.5
CVE-2007-1343
includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote …
Webcalendar
Patch available
MEDIUM 6.8
CVE-2006-6669
Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web scrip…
Webcalendar
Mitigation only
MEDIUM 6.4
CVE-2006-2762
PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL i…
Webcalendar
Mitigation only
MEDIUM 5.0
CVE-2006-2247
WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enume…
Webcalendar
Mitigation only
MEDIUM 5.0
CVE-2006-1537
Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests…
Webcalendar
Mitigation only
HIGH 7.5
CVE-2005-3984
SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_repor…
Webcalendar
Patch available
MEDIUM 5.0
CVE-2005-3982EPSS 7%
CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response …
Webcalendar
Patch available
HIGH 7.5
CVE-2005-3949
Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to…
Webcalendar
Mitigation only
MEDIUM 5.0
CVE-2005-3961
export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter.
Webcalendar
Mitigation only
HIGH 7.5
CVE-2005-2717
PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, …
Webcalendar
Patch available
HIGH 7.5
CVE-2005-2320
WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.
Webcalendar
Patch available
MEDIUM 6.4
CVE-2005-0474
SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL comma…
Webcalendar
Patch available
HIGH 7.5
CVE-2004-1508
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
Webcalendar
Mitigation only
MEDIUM 5.0
CVE-2004-1507
CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform H…
Webcalendar
No fix yet
MEDIUM 5.0
CVE-2002-2065
WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extens…
Webcalendar
Patch available
HIGH 7.5
CVE-2001-0477
Vulnerability in WebCalendar 0.9.26 allows remote command execution.
Webcalendar
Patch available