CVE-2005-3982

CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webcalendar:webcalendar:1.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://secunia.com/advisories/17848 - Patch, Vendor Advisory () http://secunia.com/advisories/17848 - Patch, Vendor Advisory
References () http://secunia.com/advisories/19240 - Patch, Vendor Advisory () http://secunia.com/advisories/19240 - Patch, Vendor Advisory
References () http://vd.lwang.org/webcalendar_multiple_vulns.txt - () http://vd.lwang.org/webcalendar_multiple_vulns.txt -
References () http://www.debian.org/security/2006/dsa-1002 - Patch, Vendor Advisory () http://www.debian.org/security/2006/dsa-1002 - Patch, Vendor Advisory
References () http://www.osvdb.org/21383 - () http://www.osvdb.org/21383 -
References () http://www.securityfocus.com/archive/1/418286/100/0/threaded - () http://www.securityfocus.com/archive/1/418286/100/0/threaded -
References () http://www.securityfocus.com/bid/15673 - () http://www.securityfocus.com/bid/15673 -
References () http://www.vupen.com/english/advisories/2005/2702 - () http://www.vupen.com/english/advisories/2005/2702 -

Information

Published : 2005-12-04 11:03

Updated : 2024-11-21 00:03


NVD link : CVE-2005-3982

Mitre link : CVE-2005-3982

CVE.ORG link : CVE-2005-3982


JSON object : View

Products Affected

webcalendar

  • webcalendar