Back to Database
Status published
High
CVE-2012-5385
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers...
Vulnerability Description
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-5385
Credits & Attribution
No credits recorded in the NVD database.
References
More from webcalendar project
View All →CVE-2013-1422
webcalendar before 1.2.7 shows the reason for a failed login...
Medium
5.3
CVE-2013-1421
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5,...
Medium
4.3
CVE-2012-5384
Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow...
Medium
4.3
CVE-2012-1496
Local file inclusion in WebCalendar before 1.2.5....
High
8.8
CVE-2012-1495
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute...
Critical
9.8
Affected Vendor
webcalendar project
View all reports →Affected Software
webcalendar
Vulnerable Versions:
1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.2, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4
Timeline
Official Publish:
October 11th, 2012
Last Modified:
September 17th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.