CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.
References
Configurations
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/17848 - Patch, Vendor Advisory | |
References | () http://secunia.com/advisories/19240 - Patch, Vendor Advisory | |
References | () http://vd.lwang.org/webcalendar_multiple_vulns.txt - | |
References | () http://www.debian.org/security/2006/dsa-1002 - Patch, Vendor Advisory | |
References | () http://www.osvdb.org/21383 - | |
References | () http://www.securityfocus.com/archive/1/418286/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/15673 - | |
References | () http://www.vupen.com/english/advisories/2005/2702 - |
Information
Published : 2005-12-04 11:03
Updated : 2024-11-21 00:03
NVD link : CVE-2005-3982
Mitre link : CVE-2005-3982
CVE.ORG link : CVE-2005-3982
JSON object : View
Products Affected
webcalendar
- webcalendar
CWE