PT-2006-1261 · Acal · Acal Calendar Project
Aliaksandr Hartsuyeu
·
Published
2006-01-12
·
Updated
2018-10-19
·
CVE-2006-0183
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ACal Calendar Project version 2.2.5
Description
A direct static code injection issue allows authenticated users to execute arbitrary PHP code. This is achieved via the
edit parameter, specifically through the edit=header value, which modifies header.php, or the edit=footer value, which modifies footer.php. The issue might be related to poor authentication.Recommendations
For ACal Calendar Project version 2.2.5, consider restricting access to the
edit.php file to prevent authenticated users from modifying header.php and footer.php files until a proper fix is applied. As a temporary workaround, limit the ability of administrators to edit code directly to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acal Calendar Project