VulnerabilityModified
CVE-2005-1147
calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.
MEDIUM 5.0EPSS 1.43%
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.43% probability · 71th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1013705Vendor Advisory
- http://www.osvdb.org/15546Vendor Advisory
- http://www.snkenjoi.com/secadv/secadv3.txtVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20102
- http://securitytracker.com/id?1013705Vendor Advisory
- http://www.osvdb.org/15546Vendor Advisory
- http://www.snkenjoi.com/secadv/secadv3.txtVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20102
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.