VYPR

WebCalendar

by Craig Knudsen

CVEs (2)

  • CVE-2012-5385Oct 11, 2012
    risk 0.00cvss epss 0.02

    install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.

  • CVE-2006-1537Mar 30, 2006
    risk 0.00cvss epss 0.02

    Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7)…