PT-2006-1283 · Unknown · Light Weight Calendar
Aliaksandr Hartsuyeu
·
Publicado
2006-01-13
·
Atualizado
2017-07-20
·
CVE-2006-0206
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Light Weight Calendar (LWC) versions 1.0 (20040909) and earlier
Description
The issue allows remote attackers to execute arbitrary PHP code via the
date parameter in "cal.php", which is included by "index.php". This enables attackers to inject and execute malicious PHP code, potentially leading to unauthorized access or control of the system.Recommendations
For Light Weight Calendar (LWC) versions 1.0 (20040909) and earlier, consider restricting access to the "cal.php" file or avoiding the use of the
date parameter in "cal.php" until a fix is available. As a temporary workaround, consider validating and sanitizing all user input to prevent malicious code injection.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Light Weight Calendar