İçeriğe atla
Noroxi

webcalendar kayıtları

webcalendar üreticisine ait 21 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
8
Düzeltme kaydı olan
%47,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

    Çubuk: toplam · koyu kısım: CISA KEV.

    Tüm kayıtlar

    21 kayıt
    • CVE-2001-0477
      31İzleyin

      Vulnerability in WebCalendar 0.9.26 allows remote command execution.

      YüksekCVSS 7,5İstismar yokEPSS %4

      webcalendar · webcalendar27 Haz 2001

    • CVE-2004-1510
      31İzleyin

      WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.

      YüksekCVSS 7,5İstismar yokEPSS %3

      webcalendar · webcalendar31 Ara 2004

    • CVE-2007-1343
      31İzleyin

      includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allow

      YüksekCVSS 7,5İstismar yokEPSS %2

      webcalendar · webcalendar8 Mar 2007

    • CVE-2005-3949
      31İzleyin

      Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid par

      YüksekCVSS 7,5İstismar yokEPSS %2

      webcalendar · webcalendar1 Ara 2005

    • CVE-2005-2717
      31İzleyin

      PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening setti

      YüksekCVSS 7,5İstismar yokEPSS %2

      webcalendar · webcalendar29 Ağu 2005

    • CVE-2004-1508
      30İzleyin

      init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.

      YüksekCVSS 7,5İstismar yokEPSS %2

      webcalendar · webcalendar31 Ara 2004

    • CVE-2005-2320
      30İzleyin

      WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.

      YüksekCVSS 7,5İstismar yokEPSS %1

      webcalendar · webcalendar19 Tem 2005

    • CVE-2005-3984
      30İzleyin

      SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to e

      YüksekCVSS 7,5İstismar yokEPSS %1

      webcalendar · webcalendar4 Ara 2005

    • CVE-2008-1954
      30İzleyin

      SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via

      YüksekCVSS 7,5Kavram kanıtıEPSS %1

      webcalendar · web calendar pro25 Nis 2008

    • CVE-2006-6669
      27İzleyin

      Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary

      OrtaCVSS 6,8İstismar yokEPSS %1

      webcalendar · webcalendar20 Ara 2006

    • CVE-2006-2762
      26İzleyin

      PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code vi

      OrtaCVSS 6,4İstismar yokEPSS %2

      webcalendar · webcalendar1 Haz 2006

    • CVE-2005-0474
      25İzleyin

      SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary

      OrtaCVSS 6,4İstismar yokEPSS %1

      webcalendar · webcalendar30 Mar 2005

    • CVE-2005-3982
      22İzleyin

      CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP

      OrtaCVSS 5,0Kavram kanıtıEPSS %7

      webcalendar · webcalendar4 Ara 2005

    • CVE-2006-1537
      21İzleyin

      Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php,

      OrtaCVSS 5,0İstismar yokEPSS %2

      webcalendar · webcalendar30 Mar 2006

    • CVE-2005-3961
      21İzleyin

      export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter.

      OrtaCVSS 5,0İstismar yokEPSS %2

      webcalendar · webcalendar1 Ara 2005

    • CVE-2006-2247
      20İzleyin

      WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers

      OrtaCVSS 5,0İstismar yokEPSS %2

      webcalendar · webcalendar9 May 2006

    • CVE-2004-1509
      20İzleyin

      validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the

      OrtaCVSS 5,0İstismar yokEPSS %2

      webcalendar · webcalendar31 Ara 2004

    • CVE-2004-1507
      20İzleyin

      CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and

      OrtaCVSS 5,0İstismar yokEPSS %1

      webcalendar · webcalendar31 Ara 2004

    • CVE-2002-2065
      20İzleyin

      WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .i

      OrtaCVSS 5,0İstismar yokEPSS %1

      webcalendar · webcalendar31 Ara 2002

    • CVE-2004-1506
      17İzleyin

      Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.

      OrtaCVSS 4,3İstismar yokEPSS %1

      webcalendar · webcalendar31 Ara 2004

    • CVE-2007-6696
      9İzleyin

      Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (

      DüşükCVSS 2,1Kavram kanıtıEPSS %2

      webcalendar · webcalendar1 Şub 2008