WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry…
Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.
webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
Local file inclusion in WebCalendar before 1.2.5.
Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via ve…