|
|
Subscribe / Log in / New account

webcalendar: information disclosure

Package(s):webcalendar CVE #(s):CVE-2006-2247
Created:May 15, 2006 Updated:May 17, 2006
Description: David Maciejak noticed that webcalendar, a PHP-Based multi-user calendar, returns different error messages on login attempts for an invalid password and a non-existing user, allowing remote attackers to gain information about valid usernames.
Alerts:
Debian DSA-1056-1 webcalendar 2006-05-15

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds