CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webcalendar | Webcalendar | 1.0.1 (including) | 1.0.1 (including) |
Webcalendar | Ubuntu | dapper | * |
Webcalendar | Ubuntu | devel | * |
Webcalendar | Ubuntu | edgy | * |