NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
66896  CVE-2005-1147  calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.    Medium  2017-07-18  2017-07-10  View
80613  CVE-2002-1660  calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.    7.5  High  2017-07-18  2017-07-10  View
65605  CVE-2006-7062  calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.    7.8  High  2016-12-20  2011-03-07  View
55411  CVE-2007-3258  calendar.php in Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via large values to the (1) year and (2) month parameters, which causes negative values to be passed to the mktime library call, and reveals the installation path in the error message.    Medium  2017-01-07  2008-09-05  View
65368  CVE-2006-6825  Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for calendar.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2016-12-20  2011-03-07  View

Page 15378 of 17672, showing 5 records out of 88360 total, starting on record 76886, ending on 76890

Actions