Back

CVE-2005-3984

SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_report_handler.php. NOTE: the startid/activity_log.php vector is already covered by CVE-2005-3949.

Published: Dec 4, 2005 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
webcalendar webcalendar 1.0.1

GitHub Security Advisory GHSA-8m2x-mm2c-xh64

SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.27%

Top 32% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub