7.5
CVSSv2

CVE-2012-5385

Published: 11/10/2012 Updated: 29/01/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

install/index.php in Craig Knudsen WebCalendar prior to 1.2.5 allows remote malicious users to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.

Vulnerable Product Search on Vulmon Subscribe to Product

webcalendar project webcalendar 1.2.2

webcalendar project webcalendar 1.2.0

webcalendar project webcalendar 1.1.1

webcalendar project webcalendar 1.0

webcalendar project webcalendar 1.2.4

webcalendar project webcalendar 1.2.3

webcalendar project webcalendar 1.1.6

webcalendar project webcalendar 1.1.5

webcalendar project webcalendar 1.1.4

webcalendar project webcalendar 1.1.3

webcalendar project webcalendar 1.2.1

webcalendar project webcalendar 1.2

webcalendar project webcalendar 1.1.2