CVE Vulnerabilities

CVE-2012-5385

Published: Oct 11, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.

Affected Software

NameVendorStart VersionEnd Version
WebcalendarWebcalendar_project1.0-rc1 (including)1.0-rc1 (including)
WebcalendarWebcalendar_project1.0-rc2 (including)1.0-rc2 (including)
WebcalendarWebcalendar_project1.0-rc3 (including)1.0-rc3 (including)
WebcalendarWebcalendar_project1.1.1 (including)1.1.1 (including)
WebcalendarWebcalendar_project1.1.2 (including)1.1.2 (including)
WebcalendarWebcalendar_project1.1.3 (including)1.1.3 (including)
WebcalendarWebcalendar_project1.1.4 (including)1.1.4 (including)
WebcalendarWebcalendar_project1.1.5 (including)1.1.5 (including)
WebcalendarWebcalendar_project1.1.6 (including)1.1.6 (including)
WebcalendarWebcalendar_project1.2-b1 (including)1.2-b1 (including)
WebcalendarWebcalendar_project1.2.0 (including)1.2.0 (including)
WebcalendarWebcalendar_project1.2.1 (including)1.2.1 (including)
WebcalendarWebcalendar_project1.2.2 (including)1.2.2 (including)
WebcalendarWebcalendar_project1.2.3 (including)1.2.3 (including)
WebcalendarWebcalendar_project1.2.4 (including)1.2.4 (including)

References