PT-2006-3946 · Codewalkers · Ltwcalendar
Spc-X
+1
·
Published
2006-06-15
·
Updated
2024-08-07
·
CVE-2006-3041
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Codewalkers Ltwcalendar version 4.1.3
Description
The issue allows remote attackers to potentially execute arbitrary PHP code via a URL in the
ltw config[include dir] parameter in the Ltwcalendar/calendar.php file. However, it is noted that the $ltw config[include dir] variable is defined as a static value in an include file before it is referenced in an include() statement, which disputes the claim of vulnerability.Recommendations
For Codewalkers Ltwcalendar version 4.1.3, consider reviewing the code to ensure the
$ltw config[include dir] variable is properly sanitized and validated to prevent potential exploitation. As a temporary workaround, consider restricting access to the calendar.php file until the issue is fully resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ltwcalendar