CVE

Id
58628  
CVE No.
CVE-2012-5385  
Status
Candidate  
Description
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.  
Phase
Assigned (20121011)  
Votes
None (candidate not yet proposed)  
Comments