CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9938 | CVE-2004-1510 | Candidate | WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php. | Assigned (20050218) | None (candidate not yet proposed) | View | |
51726 | CVE-2011-3814 | Candidate | WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
18351 | CVE-2006-2247 | Candidate | WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames. | Assigned (20060508) | None (candidate not yet proposed) | View | |
6447 | CVE-2002-2065 | Candidate | WebCalendar 0.9.34 and earlier with "browsing in includes directory" enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root. | Assigned (20050714) | None (candidate not yet proposed) | View | |
10136 | CVE-2004-1708 | Candidate | Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections. | Assigned (20050226) | None (candidate not yet proposed) | View |
Page 388 of 20943, showing 5 records out of 104715 total, starting on record 1936, ending on 1940