Vulnerability Name:

CVE-2005-3949 (CCN-23369)

Assigned:2005-11-28
Published:2005-11-28
Updated:2018-10-19
Summary:Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php, and (4) multiple parameters to export_handler.php.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Data Manipulation
References:Source: CCN
Type: Full-Disclosure Mailing List, Mon Nov 28 2005 - 10:47:22 CST
WebCalendar Multiple Vulnerabilities

Source: MITRE
Type: CNA
CVE-2005-3949

Source: CCN
Type: SA17784
WebCalendar SQL Injection and Local File Overwrite Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
17784

Source: SECUNIA
Type: UNKNOWN
19240

Source: SREASON
Type: UNKNOWN
215

Source: CONFIRM
Type: UNKNOWN
http://sourceforge.net/forum/forum.php?thread_id=1392833&forum_id=11587

Source: CCN
Type: WebCalendar Web site
Project: WebCalendar: Summary

Source: DEBIAN
Type: UNKNOWN
DSA-1002

Source: DEBIAN
Type: DSA-1002
webcalendar -- several vulnerabilities

Source: CCN
Type: WebCalendar Download Web page
WebCalendar

Source: OSVDB
Type: UNKNOWN
21216

Source: OSVDB
Type: UNKNOWN
21217

Source: OSVDB
Type: UNKNOWN
21218

Source: OSVDB
Type: UNKNOWN
21219

Source: CCN
Type: OSVDB ID: 21216
WebCalendar activity_log.php startid Parameter SQL Injection

Source: CCN
Type: OSVDB ID: 21217
WebCalendar admin_handler.php Multiple Parameter SQL Injection

Source: CCN
Type: OSVDB ID: 21218
WebCalendar edit_template.php template Parameter SQL Injection

Source: CCN
Type: OSVDB ID: 21219
WebCalendar export_handler.php Multiple Parameter SQL Injection

Source: BUGTRAQ
Type: UNKNOWN
20051128 WebCalendar Multiple Vulnerabilities

Source: BUGTRAQ
Type: UNKNOWN
20051201 WebCalendar Multiple Vulnerabilities.

Source: BID
Type: UNKNOWN
15606

Source: CCN
Type: BID-15606
WebCalendar Multiple SQL Injection Vulnerabilities

Source: BID
Type: UNKNOWN
15608

Source: CCN
Type: BID-15608
WebCalendar Export_Handler.PHP File Corruption Vulnerability

Source: BID
Type: UNKNOWN
15662

Source: CCN
Type: BID-15662
WebCalendar Multiple SQL Injection Vulnerabilities

Source: MISC
Type: Vendor Advisory
http://www.ush.it/2005/11/28/webcalendar-multiple-vulnerabilities

Source: CCN
Type: ush.it - a beautiful place Web site
WebCalendar Multiple Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2005-2643

Source: XF
Type: UNKNOWN
webcalendar-multiple-scripts-sql-injection(23369)

Source: XF
Type: UNKNOWN
webcalendar-multiple-scripts-sql-injection(23369)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:webcalendar:webcalendar:1.0.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:webcalendar:webcalendar:1.0.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:1002
    V
    several vulnerabilities
    2006-03-15
    BACK
    webcalendar webcalendar 1.0.1
    webcalendar webcalendar 1.0.1
    debian debian linux 3.1