PT-2002-2785 · Unknown · Webcalendar
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2065
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
WebCalendar versions 0.9.34 and earlier
Description:
The issue allows remote attackers to read arbitrary include files with .inc extensions from the web root when 'browsing in includes directory' is enabled.
Recommendations:
For WebCalendar versions 0.9.34 and earlier, disable the 'browsing in includes directory' option to prevent remote attackers from reading arbitrary include files.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webcalendar