Back
CVE-2005-0474
SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.
Published: Mar 30, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| webcalendar | webcalendar | 0.9.45 |
GitHub Security Advisory GHSA-4mmm-jj36-wmc5
SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45...
References (12)
- http://marc.info/?l=bugtraq&m=110868446431706&w=2
- http://secunia.com/advisories/14319 Patch, Vendor Advisory
- http://securitytracker.com/id?1013231
- http://www.osvdb.org/13918
- http://www.scovettalabs.com/advisory/SCL-2005.001.txt Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19369
- http://marc.info/?l=bugtraq&m=110868446431706&w=2
- http://secunia.com/advisories/14319 Patch, Vendor Advisory
- http://securitytracker.com/id?1013231
- http://www.osvdb.org/13918
- http://www.scovettalabs.com/advisory/SCL-2005.001.txt Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19369
Risk Scores
CVSS Score
6.4 / 10
EPSS Score
1.44%
Top 29% most likely to be exploited
Threat Score
26 / 100
Data Sources
NVD
EPSS
GitHub