PT-2006-3946 · Codewalkers · Ltwcalendar

Spc-X

+1

·

Publicado

2006-06-15

·

Atualizado

2024-08-07

·

CVE-2006-3041

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Codewalkers Ltwcalendar version 4.1.3
Description The issue allows remote attackers to potentially execute arbitrary PHP code via a URL in the ltw config[include dir] parameter in the Ltwcalendar/calendar.php file. However, it is noted that the $ltw config[include dir] variable is defined as a static value in an include file before it is referenced in an include() statement, which disputes the claim of vulnerability.
Recommendations For Codewalkers Ltwcalendar version 4.1.3, consider reviewing the code to ensure the $ltw config[include dir] variable is properly sanitized and validated to prevent potential exploitation. As a temporary workaround, consider restricting access to the calendar.php file until the issue is fully resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3041

Produtos afetados

Ltwcalendar