Lucene search

K
cveMitreCVE-2002-2065
HistoryJul 14, 2005 - 4:00 a.m.

CVE-2002-2065

2005-07-1404:00:00
mitre
web.nvd.nist.gov
26
webcalendar
cve-2002-2065
information security
remote attackers
web root
arbitrary include files

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.005

Percentile

75.9%

WebCalendar 0.9.34 and earlier with ‘browsing in includes directory’ enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root.

Affected configurations

Nvd
Node
webcalendarwebcalendarMatch0.9.31
OR
webcalendarwebcalendarMatch0.9.32
OR
webcalendarwebcalendarMatch0.9.33
OR
webcalendarwebcalendarMatch0.9.34
VendorProductVersionCPE
webcalendarwebcalendar0.9.31cpe:2.3:a:webcalendar:webcalendar:0.9.31:*:*:*:*:*:*:*
webcalendarwebcalendar0.9.32cpe:2.3:a:webcalendar:webcalendar:0.9.32:*:*:*:*:*:*:*
webcalendarwebcalendar0.9.33cpe:2.3:a:webcalendar:webcalendar:0.9.33:*:*:*:*:*:*:*
webcalendarwebcalendar0.9.34cpe:2.3:a:webcalendar:webcalendar:0.9.34:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.005

Percentile

75.9%

Related for CVE-2002-2065