Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] WebCalendar Multiple Vulnerabilities |
|---|---|
| Date: | Mon, 28 Nov 2005 17:47:22 +0100 |
WebCalendar Multiple Vulnerabilities
Name Multiple Vulnerabilities in WebCalendar
Systems Affected WebCalendar (verified on 1.0.1)
Severity Medium Risk
Vendor www.k5n.us/webcalendar.php?topic=About
Advisory
http://www.ush.it/2005/11/28/webcalendar-multiple-vulnerabilities/
Advisory
http://www.ush.it/team/ascii/hack-WebCalendar/advisory.txt
Author Francesco "ÂaScii"Â Ongaro (ascii at katamail . com)
Date 20051128WebCalendar is vulnerable to four SQL Injection (files activity_log.php, admin_handler.php, edit_template.php and export_handler.php) and one local file overwrite (export_handler.php), input validation will fix.
Advisory released on 20051128: WebCalendar Multiple Vulnerabilities http://www.ush.it/2005/11/28/webcalendar-multiple-vulnerabilities/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] Php Web Statistik Multiple Vulnerabilities, ascii |
|---|---|
| Next by Date: | [Full-disclosure] [ GLSA 200511-23 ] chmlib, KchmViewer: Stack-based buffer overflow, koon |
| Previous by Thread: | [Full-disclosure] Php Web Statistik Multiple Vulnerabilities, ascii |
| Next by Thread: | [Full-disclosure] Re: WebCalendar Multiple Vulnerabilities, Paul Laudanski |
| Indexes: | [Date] [Thread] [Top] [All Lists] |