vendor:
WebCalendar
by:
Unknown
N/A
CVSS
N/A
Cross-Site Scripting (XSS), HTTP Response Splitting, Authentication Bypass
79, 113
CWE
Product Name: WebCalendar
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
Unknown
Multiple Vulnerabilities in WebCalendar
Multiple remote vulnerabilities are reported to exist in WebCalendar. Multiple cross-site scripting vulnerabilities, an HTTP response splitting vulnerability, and two authentication bypass vulnerabilities are reported to exist in many different scripts in the affected application.
Mitigation:
Fixes are reported to exist in the CVS version of the software.