Vulnerabilities > CVE-2005-2320 - Unspecified vulnerability in Webcalendar

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
webcalendar
nessus

Summary

WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-766.NASL
    descriptionA vulnerability has been discovered in webcalendar, a PHP based multi-user calendar, that can lead to the disclosure of sensitive information to unauthorised parties.
    last seen2020-06-01
    modified2020-06-02
    plugin id19315
    published2005-07-31
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19315
    titleDebian DSA-766-1 : webcalendar - authorisation failure
  • NASL familyCGI abuses
    NASL idWEBCALENDAR_ASSISTANT_EDIT.NASL
    descriptionThe remote version of WebCalendar fails to restrict access to the script
    last seen2020-06-01
    modified2020-06-02
    plugin id18571
    published2005-06-28
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/18571
    titleWebCalendar assistant_edit.php Unauthorized Access
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_07EAD557A22011DAB410000E0C2E438A.NASL
    descriptionSecurityFocus reports that WebCalendar is affected by an unauthorized access vulnerability. The vulnerability is caused by improper checking of the authentication mechanism before access is being permitted to the
    last seen2020-06-01
    modified2020-06-02
    plugin id21380
    published2006-05-13
    reporterThis script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/21380
    titleFreeBSD : WebCalendar -- unauthorized access vulnerability (07ead557-a220-11da-b410-000e0c2e438a)