Lucene search

K
cveMitreCVE-2012-5385
HistoryOct 11, 2012 - 3:55 p.m.

CVE-2012-5385

2012-10-1115:55:03
CWE-264
mitre
web.nvd.nist.gov
27
cve-2012-5385
webcalendar
remote code execution
security vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.008

Percentile

82.2%

install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.

Affected configurations

Nvd
Node
webcalendar_projectwebcalendarMatch1.0rc1
OR
webcalendar_projectwebcalendarMatch1.0rc2
OR
webcalendar_projectwebcalendarMatch1.0rc3
OR
webcalendar_projectwebcalendarMatch1.1.1
OR
webcalendar_projectwebcalendarMatch1.1.2
OR
webcalendar_projectwebcalendarMatch1.1.3
OR
webcalendar_projectwebcalendarMatch1.1.4
OR
webcalendar_projectwebcalendarMatch1.1.5
OR
webcalendar_projectwebcalendarMatch1.1.6
OR
webcalendar_projectwebcalendarMatch1.2b1
OR
webcalendar_projectwebcalendarMatch1.2.0
OR
webcalendar_projectwebcalendarMatch1.2.1
OR
webcalendar_projectwebcalendarMatch1.2.2
OR
webcalendar_projectwebcalendarMatch1.2.3
OR
webcalendar_projectwebcalendarMatch1.2.4
VendorProductVersionCPE
webcalendar_projectwebcalendar1.0cpe:2.3:a:webcalendar_project:webcalendar:1.0:rc1:*:*:*:*:*:*
webcalendar_projectwebcalendar1.0cpe:2.3:a:webcalendar_project:webcalendar:1.0:rc2:*:*:*:*:*:*
webcalendar_projectwebcalendar1.0cpe:2.3:a:webcalendar_project:webcalendar:1.0:rc3:*:*:*:*:*:*
webcalendar_projectwebcalendar1.1.1cpe:2.3:a:webcalendar_project:webcalendar:1.1.1:*:*:*:*:*:*:*
webcalendar_projectwebcalendar1.1.2cpe:2.3:a:webcalendar_project:webcalendar:1.1.2:*:*:*:*:*:*:*
webcalendar_projectwebcalendar1.1.3cpe:2.3:a:webcalendar_project:webcalendar:1.1.3:*:*:*:*:*:*:*
webcalendar_projectwebcalendar1.1.4cpe:2.3:a:webcalendar_project:webcalendar:1.1.4:*:*:*:*:*:*:*
webcalendar_projectwebcalendar1.1.5cpe:2.3:a:webcalendar_project:webcalendar:1.1.5:*:*:*:*:*:*:*
webcalendar_projectwebcalendar1.1.6cpe:2.3:a:webcalendar_project:webcalendar:1.1.6:*:*:*:*:*:*:*
webcalendar_projectwebcalendar1.2cpe:2.3:a:webcalendar_project:webcalendar:1.2:b1:*:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.008

Percentile

82.2%

Related for CVE-2012-5385