Total vulnerabilities in the database
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.
Software | From | Fixed in |
---|---|---|
webcalendar_project / webcalendar | 1.0-rc1 | 1.0-rc1.x |
webcalendar_project / webcalendar | 1.0-rc2 | 1.0-rc2.x |
webcalendar_project / webcalendar | 1.0-rc3 | 1.0-rc3.x |
webcalendar_project / webcalendar | 1.1.1 | 1.1.1.x |
webcalendar_project / webcalendar | 1.1.2 | 1.1.2.x |
webcalendar_project / webcalendar | 1.1.3 | 1.1.3.x |
webcalendar_project / webcalendar | 1.1.4 | 1.1.4.x |
webcalendar_project / webcalendar | 1.1.5 | 1.1.5.x |
webcalendar_project / webcalendar | 1.1.6 | 1.1.6.x |
webcalendar_project / webcalendar | 1.2-b1 | 1.2-b1.x |
webcalendar_project / webcalendar | 1.2.0 | 1.2.0.x |
webcalendar_project / webcalendar | 1.2.1 | 1.2.1.x |
webcalendar_project / webcalendar | 1.2.2 | 1.2.2.x |
webcalendar_project / webcalendar | 1.2.3 | 1.2.3.x |
webcalendar_project / webcalendar | 1.2.4 | 1.2.4.x |