PT-2005-5015 · Webcal · Webcal

Stan Bubrouski

·

Published

2005-12-17

·

Updated

2018-10-19

·

CVE-2005-4327

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WebCal versions 1.11 through 3.04
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via several parameters to webcal.cgi, including the function, year, and date parameters, as well as through new calendar entries and notes for entries.
Recommendations For WebCal versions 1.11 through 3.04, consider restricting access to the webcal.cgi endpoint until a fix is available. As a temporary workaround, avoid using the function, year, and date parameters in the webcal.cgi endpoint. Additionally, restrict the creation of new calendar entries and editing of notes for existing entries to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4327

Affected Products

Webcal