Unrated severityNVD Advisory· Published Mar 8, 2007· Updated Apr 23, 2026
CVE-2007-1343
CVE-2007-1343
Description
includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues.
Affected products
5cpe:2.3:a:webcalendar:webcalendar:1.0.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:webcalendar:webcalendar:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:webcalendar:webcalendar:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:webcalendar:webcalendar:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:webcalendar:webcalendar:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:webcalendar:webcalendar:1.0.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/24403nvdPatchVendor Advisory
- sourceforge.net/project/shownotes.phpnvdPatch
- webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.phpnvdPatch
- webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.phpnvdPatch
- www.securityfocus.com/bid/22834nvdPatchVendor Advisory
- secunia.com/advisories/24519nvd
- sourceforge.net/mailarchive/forum.phpnvd
- www.debian.org/security/2007/dsa-1267nvd
- www.vupen.com/english/advisories/2007/0851nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/32832nvd
News mentions
0No linked articles in our index yet.