PT-2005-5015 · Webcal · Webcal

Stan Bubrouski

·

Publicado

2005-12-17

·

Atualizado

2018-10-19

·

CVE-2005-4327

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WebCal versions 1.11 through 3.04
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via several parameters to webcal.cgi, including the function, year, and date parameters, as well as through new calendar entries and notes for entries.
Recommendations For WebCal versions 1.11 through 3.04, consider restricting access to the webcal.cgi endpoint until a fix is available. As a temporary workaround, avoid using the function, year, and date parameters in the webcal.cgi endpoint. Additionally, restrict the creation of new calendar entries and editing of notes for existing entries to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4327

Produtos afetados

Webcal