PT-2006-3946 · Codewalkers · Ltwcalendar

Spc-X

+1

·

Published

2006-06-15

·

Updated

2024-08-07

·

CVE-2006-3041

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Codewalkers Ltwcalendar version 4.1.3
Description The issue allows remote attackers to potentially execute arbitrary PHP code via a URL in the ltw config[include dir] parameter in the Ltwcalendar/calendar.php file. However, it is noted that the $ltw config[include dir] variable is defined as a static value in an include file before it is referenced in an include() statement, which disputes the claim of vulnerability.
Recommendations For Codewalkers Ltwcalendar version 4.1.3, consider reviewing the code to ensure the $ltw config[include dir] variable is properly sanitized and validated to prevent potential exploitation. As a temporary workaround, consider restricting access to the calendar.php file until the issue is fully resolved.

Fix

Related Identifiers

CVE-2006-3041

Affected Products

Ltwcalendar