[Full-disclosure] WebCalendar Multiple Vulnerabilities

From: ascii (ascii_at_katamail.com)
Date: 11/28/05

  • Next message: koon_at_gentoo.org: "[Full-disclosure] [ GLSA 200511-23 ] chmlib, KchmViewer: Stack-based buffer overflow"
    Date: Mon, 28 Nov 2005 17:47:22 +0100
    To: full-disclosure@lists.grok.org.uk, ml@sikurezza.org, bugtraq@securityfocus.com, news@securiteam.com, bugs@securitytracker.com, vuln@secunia.com
    
    

    WebCalendar Multiple Vulnerabilities
            
      Name Multiple Vulnerabilities in WebCalendar
      Systems Affected WebCalendar (verified on 1.0.1)
      Severity Medium Risk
      Vendor www.k5n.us/webcalendar.php?topic=About
      Advisory
       http://www.ush.it/2005/11/28/webcalendar-multiple-vulnerabilities/
      Advisory
       http://www.ush.it/team/ascii/hack-WebCalendar/advisory.txt
      Author Francesco "“aScii"” Ongaro (ascii at katamail . com)
      Date 20051128

    WebCalendar is vulnerable to four SQL Injection (files activity_log.php,
    admin_handler.php, edit_template.php and export_handler.php) and one
    local file overwrite (export_handler.php), input validation will fix.

    Advisory released on 20051128:
    WebCalendar Multiple Vulnerabilities
    http://www.ush.it/2005/11/28/webcalendar-multiple-vulnerabilities/

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: koon_at_gentoo.org: "[Full-disclosure] [ GLSA 200511-23 ] chmlib, KchmViewer: Stack-based buffer overflow"

    Relevant Pages

    • WebCalendar Multiple Vulnerabilities
      ... WebCalendar Multiple Vulnerabilities ... Advisory ... WebCalendar is vulnerable to four SQL Injection (files activity_log.php, ... local file overwrite, input validation will fix. ...
      (Bugtraq)
    • WebCalendar Multiple Vulnerabilities.
      ... WebCalendar Multiple Vulnerabilities. ... Author: lwang ... WebCalendar is a PHP application used to maintain a calendar for one or more persons and for a variety of purposes. ... SQL Injection ...
      (Bugtraq)