CVE-2012-5385

install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:webcalendar_project:webcalendar:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.0:rc3:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar_project:webcalendar:1.2:b1:*:*:*:*:*:*

Information

Published : 2012-10-11 08:55

Updated : 2020-01-29 11:18


NVD link : CVE-2012-5385

Mitre link : CVE-2012-5385


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

webcalendar_project

  • webcalendar