VYPR

Web Calendar Pro

by Webcalendar

CVEs (3)

  • CVE-2008-5062Nov 13, 2008
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory traversal sequences in the thefile parameter.

  • CVE-2008-5061Nov 13, 2008
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL.

  • CVE-2008-1954Apr 25, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.