NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
68021 | CVE-2005-2320 | WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
71889 | CVE-2004-1510 | WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
10386 | CVE-2011-3814 | WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-10-12 | View | |
60950 | CVE-2006-2247 | WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
81016 | CVE-2002-2065 | WebCalendar 0.9.34 and earlier with "browsing in includes directory" enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 421 of 17672, showing 5 records out of 88360 total, starting on record 2101, ending on 2105