CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9938  CVE-2004-1510  Candidate  WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.  Assigned (20050218)  None (candidate not yet proposed)    View
51726  CVE-2011-3814  Candidate  WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
18351  CVE-2006-2247  Candidate  WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.  Assigned (20060508)  None (candidate not yet proposed)    View
6447  CVE-2002-2065  Candidate  WebCalendar 0.9.34 and earlier with "browsing in includes directory" enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root.  Assigned (20050714)  None (candidate not yet proposed)    View
10136  CVE-2004-1708  Candidate  Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.  Assigned (20050226)  None (candidate not yet proposed)    View

Page 388 of 20943, showing 5 records out of 104715 total, starting on record 1936, ending on 1940

Actions