漏洞信息详情
WebCalendar多个远程漏洞
- CNNVD编号:CNNVD-200412-994
- 危害等级: 中危
![图片[1]-WebCalendar多个远程漏洞-一一网](https://www.proyy.com/skycj/data/images/2021-09-07/30f462579bec41fc25e0b1d57503e6d6.png)
- CVE编号:
CVE-2004-1507
- 漏洞类型:
设计错误
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
webcalendar - 漏洞来源:
Joxean Koret
-
漏洞简介
WebCalendar的login.php存在CRLF注入漏洞。远程攻击者通过return_path参数和执行HTTP Response Splitting攻击修改服务器中预期的HTML内容,从而注入CRLF序列。
漏洞公告
It is reported that some, or all of these issues have been corrected in the CVS versions of the package. This has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com
参考网址
来源: XF
名称: webcalendar-response-splitting(18027)
链接:http://xforce.iss.net/xforce/xfdb/18027
来源: BID
名称: 11651
链接:http://www.securityfocus.com/bid/11651
来源: SECUNIA
名称: 13164
链接:http://secunia.com/advisories/13164
来源: BUGTRAQ
名称: 20041109 Multiple Vulnerabilities in WebCalendar
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110011618724455&w=2





















![[桜井宁宁]COS和泉纱雾超可爱写真福利集-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/4d3cf227a85d7e79f5d6b4efb6bde3e8.jpg)

![[桜井宁宁] 爆乳奶牛少女cos写真-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/d40483e126fcf567894e89c65eaca655.jpg)