Back

CVE-2005-0474

SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.

Published: Mar 30, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
webcalendar webcalendar 0.9.45

GitHub Security Advisory GHSA-4mmm-jj36-wmc5

SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.44%

Top 29% most likely to be exploited

Threat Score 26 / 100

Data Sources

NVD EPSS GitHub