CVE Database
/

CVE-2006-1537

Back to search

CVE-2006-1537

Published: Mar 30, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9) includes/js/admin.php, (10) includes/js/edit_entry.php, (11) includes/js/edit_layer.php, (12) includes/js/export_import.php, (13) includes/js/popups.php, (14) includes/js/pref.php, or (15) includes/menu/index.php, which reveal the path in various error messages.

VendorProductVersions

n/a

n/a

affected
n/a

References

24523
vdb-entry
x_refsource_OSVDB
24535
vdb-entry
x_refsource_OSVDB
651
third-party-advisory
x_refsource_SREASON
24534
vdb-entry
x_refsource_OSVDB
24526
vdb-entry
x_refsource_OSVDB
24531
vdb-entry
x_refsource_OSVDB
24529
vdb-entry
x_refsource_OSVDB
24524
vdb-entry
x_refsource_OSVDB
24528
vdb-entry
x_refsource_OSVDB
24525
vdb-entry
x_refsource_OSVDB
24533
vdb-entry
x_refsource_OSVDB
24532
vdb-entry
x_refsource_OSVDB
24530
vdb-entry
x_refsource_OSVDB
24527
vdb-entry
x_refsource_OSVDB
24522
vdb-entry
x_refsource_OSVDB
24536
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now