Lucene search

K
nvd[email protected]NVD:CVE-2005-3982
HistoryDec 04, 2005 - 11:03 a.m.

CVE-2005-3982

2005-12-0411:03:00
web.nvd.nist.gov
1

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.048

Percentile

92.8%

CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.

Affected configurations

Nvd
Node
webcalendarwebcalendarMatch1.0.1
VendorProductVersionCPE
webcalendarwebcalendar1.0.1cpe:2.3:a:webcalendar:webcalendar:1.0.1:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.048

Percentile

92.8%