Vulnerability Name: | CVE-2007-1343 (CCN-32832) | ||||||||
Assigned: | 2007-03-04 | ||||||||
Published: | 2007-03-04 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-1343 Source: CCN Type: SA24403 WebCalendar "noSet" Variable Overwrite Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 24403 Source: SECUNIA Type: UNKNOWN 24519 Source: MLIST Type: UNKNOWN [webcalendar-announce] 20070304 Announce: Release 1.0.5 (security patch) Source: CONFIRM Type: Patch http://sourceforge.net/project/shownotes.php?group_id=3870&release_id=491130 Source: CCN Type: SourceForge.net: Files WebCalendar - File Release Notes and Changelog - Release Name: 1.0.5 Source: CONFIRM Type: Patch http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?r1=1.211.2.7&r2=1.211.2.8 Source: CONFIRM Type: Patch http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?view=log Source: DEBIAN Type: UNKNOWN DSA-1267 Source: DEBIAN Type: DSA-1267 webcalendar -- missing input sanitising Source: CCN Type: OSVDB ID: 33867 WebCalendar includes/functions.php noSet Variable Overwrite Source: BID Type: Patch, Vendor Advisory 22834 Source: CCN Type: BID-22834 WebCalendar Certain Variable Overwrite Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-0851 Source: XF Type: UNKNOWN webcalendar-noset-variable-overwrite(32832) Source: XF Type: UNKNOWN webcalendar-noset-variable-overwrite(32832) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |