Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Web Calendar Pro HIGH 7.5
CVE-2008-1954

SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user…

Fix: after 4.1
Fix from $1,950 2008-04-25
Webcalendar HIGH 7.5
CVE-2007-1343

includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote …

Patch available
Fix from $1,950 2007-03-08
Webcalendar MEDIUM 6.8
CVE-2006-6669

Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web scrip…

Mitigation only
Fix from $1,600 2006-12-20
Webcalendar MEDIUM 6.4
CVE-2006-2762

PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL i…

Mitigation only
Fix from $1,600 2006-06-02
Webcalendar MEDIUM 5.0
CVE-2006-2247

WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enume…

Mitigation only
Fix from $1,600 2006-05-09
Webcalendar MEDIUM 5.0
CVE-2006-1537

Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests…

Mitigation only
Fix from $1,600 2006-03-30
Webcalendar HIGH 7.5
CVE-2005-3984

SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_repor…

Patch available
Fix from $1,950 2005-12-04
Webcalendar MEDIUM 5.0
CVE-2005-3982EPSS 7%

CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response …

Patch available
Fix from $1,600 2005-12-04
Webcalendar HIGH 7.5
CVE-2005-3949

Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to…

Mitigation only
Fix from $1,950 2005-12-01
Webcalendar MEDIUM 5.0
CVE-2005-3961

export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter.

Mitigation only
Fix from $1,600 2005-12-01
Webcalendar HIGH 7.5
CVE-2005-2717

PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, …

Patch available
Fix from $1,950 2005-08-29
Webcalendar HIGH 7.5
CVE-2005-2320

WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.

Patch available
Fix from $1,950 2005-07-19
Webcalendar MEDIUM 6.4
CVE-2005-0474

SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL comma…

Patch available
Fix from $1,600 2005-03-30
Webcalendar HIGH 7.5
CVE-2004-1508

init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.

Mitigation only
Fix from $1,950 2004-12-31
Webcalendar MEDIUM 5.0
CVE-2004-1507

CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform H…

No fix yet
Fix from $1,600 2004-12-31
Webcalendar MEDIUM 5.0
CVE-2002-2065

WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extens…

Patch available
Fix from $1,600 2002-12-31
Webcalendar HIGH 7.5
CVE-2001-0477

Vulnerability in WebCalendar 0.9.26 allows remote command execution.

Patch available
Fix from $1,950 2001-06-27