PT-2006-1261 · Acal · Acal Calendar Project

Aliaksandr Hartsuyeu

·

Published

2006-01-12

·

Updated

2018-10-19

·

CVE-2006-0183

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ACal Calendar Project version 2.2.5
Description A direct static code injection issue allows authenticated users to execute arbitrary PHP code. This is achieved via the edit parameter, specifically through the edit=header value, which modifies header.php, or the edit=footer value, which modifies footer.php. The issue might be related to poor authentication.
Recommendations For ACal Calendar Project version 2.2.5, consider restricting access to the edit.php file to prevent authenticated users from modifying header.php and footer.php files until a proper fix is applied. As a temporary workaround, limit the ability of administrators to edit code directly to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0183

Affected Products

Acal Calendar Project