Loading
Generated remediation guidance and an executive summary. No account required.
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.
Use CWE-264, Webcalendar Project vendor hub and Webcalendar product page to widen CVE-2012-5385 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2012-1495, CVE-2012-1496 and CVE-2024-22635 for nearby disclosures in the same product family.