webcalendar kayıtları
webcalendar üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %47,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2001-0477İstismar yok | Vulnerability in WebCalendar 0.9.26 allows remote command execution.webcalendar · webcalendar | Yüksek7,5 | — | %4,0 | 27 Haz 2001 |
31İzleyin | CVE-2004-1510İstismar yok | WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.webcalendar · webcalendar | Yüksek7,5 | — | %2,7 | 31 Ara 2004 |
31İzleyin | CVE-2007-1343İstismar yok | includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allowwebcalendar · webcalendar | Yüksek7,5 | — | %2,1 | 8 Mar 2007 |
31İzleyin | CVE-2005-3949İstismar yok | Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parwebcalendar · webcalendar | Yüksek7,5 | — | %2,1 | 1 Ara 2005 |
31İzleyin | CVE-2005-2717İstismar yok | PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settiwebcalendar · webcalendar | Yüksek7,5 | — | %2,0 | 29 Ağu 2005 |
30İzleyin | CVE-2004-1508İstismar yok | init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.webcalendar · webcalendar | Yüksek7,5 | — | %1,6 | 31 Ara 2004 |
30İzleyin | CVE-2005-2320İstismar yok | WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.webcalendar · webcalendar | Yüksek7,5 | — | %1,4 | 19 Tem 2005 |
30İzleyin | CVE-2005-3984İstismar yok | SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to ewebcalendar · webcalendar · CWE-89 | Yüksek7,5 | — | %1,3 | 4 Ara 2005 |
30İzleyin | CVE-2008-1954Kavram kanıtı | SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands viawebcalendar · web calendar pro · CWE-89 | Yüksek7,5 | — | %1,2 | 25 Nis 2008 |
27İzleyin | CVE-2006-6669İstismar yok | Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary webcalendar · webcalendar | Orta6,8 | — | %1,4 | 20 Ara 2006 |
26İzleyin | CVE-2006-2762İstismar yok | PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code viwebcalendar · webcalendar | Orta6,4 | — | %2,2 | 1 Haz 2006 |
25İzleyin | CVE-2005-0474İstismar yok | SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary webcalendar · webcalendar | Orta6,4 | — | %1,4 | 30 Mar 2005 |
22İzleyin | CVE-2005-3982Kavram kanıtı | CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP webcalendar · webcalendar | Orta5,0 | — | %7,1 | 4 Ara 2005 |
21İzleyin | CVE-2006-1537İstismar yok | Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, webcalendar · webcalendar | Orta5,0 | — | %2,3 | 30 Mar 2006 |
21İzleyin | CVE-2005-3961İstismar yok | export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter.webcalendar · webcalendar | Orta5,0 | — | %2,2 | 1 Ara 2005 |
20İzleyin | CVE-2006-2247İstismar yok | WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackerswebcalendar · webcalendar | Orta5,0 | — | %1,7 | 9 May 2006 |
20İzleyin | CVE-2004-1509İstismar yok | validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the webcalendar · webcalendar | Orta5,0 | — | %1,6 | 31 Ara 2004 |
20İzleyin | CVE-2004-1507İstismar yok | CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and webcalendar · webcalendar | Orta5,0 | — | %1,5 | 31 Ara 2004 |
20İzleyin | CVE-2002-2065İstismar yok | WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .iwebcalendar · webcalendar | Orta5,0 | — | %1,4 | 31 Ara 2002 |
17İzleyin | CVE-2004-1506İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.webcalendar · webcalendar | Orta4,3 | — | %1,3 | 31 Ara 2004 |
9İzleyin | CVE-2007-6696Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (webcalendar · webcalendar · CWE-79 | Düşük2,1 | — | %1,7 | 1 Şub 2008 |
- CVE-2001-047731İzleyin
Vulnerability in WebCalendar 0.9.26 allows remote command execution.
YüksekCVSS 7,5İstismar yokEPSS %4webcalendar · webcalendar27 Haz 2001
- CVE-2004-151031İzleyin
WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.
YüksekCVSS 7,5İstismar yokEPSS %3webcalendar · webcalendar31 Ara 2004
- CVE-2007-134331İzleyin
includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allow
YüksekCVSS 7,5İstismar yokEPSS %2webcalendar · webcalendar8 Mar 2007
- CVE-2005-394931İzleyin
Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid par
YüksekCVSS 7,5İstismar yokEPSS %2webcalendar · webcalendar1 Ara 2005
- CVE-2005-271731İzleyin
PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening setti
YüksekCVSS 7,5İstismar yokEPSS %2webcalendar · webcalendar29 Ağu 2005
- CVE-2004-150830İzleyin
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
YüksekCVSS 7,5İstismar yokEPSS %2webcalendar · webcalendar31 Ara 2004
- CVE-2005-232030İzleyin
WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.
YüksekCVSS 7,5İstismar yokEPSS %1webcalendar · webcalendar19 Tem 2005
- CVE-2005-398430İzleyin
SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to e
YüksekCVSS 7,5İstismar yokEPSS %1webcalendar · webcalendar4 Ara 2005
- CVE-2008-195430İzleyin
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1webcalendar · web calendar pro25 Nis 2008
- CVE-2006-666927İzleyin
Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary
OrtaCVSS 6,8İstismar yokEPSS %1webcalendar · webcalendar20 Ara 2006
- CVE-2006-276226İzleyin
PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code vi
OrtaCVSS 6,4İstismar yokEPSS %2webcalendar · webcalendar1 Haz 2006
- CVE-2005-047425İzleyin
SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary
OrtaCVSS 6,4İstismar yokEPSS %1webcalendar · webcalendar30 Mar 2005
- CVE-2005-398222İzleyin
CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP
OrtaCVSS 5,0Kavram kanıtıEPSS %7webcalendar · webcalendar4 Ara 2005
- CVE-2006-153721İzleyin
Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php,
OrtaCVSS 5,0İstismar yokEPSS %2webcalendar · webcalendar30 Mar 2006
- CVE-2005-396121İzleyin
export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter.
OrtaCVSS 5,0İstismar yokEPSS %2webcalendar · webcalendar1 Ara 2005
- CVE-2006-224720İzleyin
WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers
OrtaCVSS 5,0İstismar yokEPSS %2webcalendar · webcalendar9 May 2006
- CVE-2004-150920İzleyin
validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the
OrtaCVSS 5,0İstismar yokEPSS %2webcalendar · webcalendar31 Ara 2004
- CVE-2004-150720İzleyin
CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and
OrtaCVSS 5,0İstismar yokEPSS %1webcalendar · webcalendar31 Ara 2004
- CVE-2002-206520İzleyin
WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .i
OrtaCVSS 5,0İstismar yokEPSS %1webcalendar · webcalendar31 Ara 2002
- CVE-2004-150617İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.
OrtaCVSS 4,3İstismar yokEPSS %1webcalendar · webcalendar31 Ara 2004
- CVE-2007-66969İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (
DüşükCVSS 2,1Kavram kanıtıEPSS %2webcalendar · webcalendar1 Şub 2008