PT-2007-2302 · Local · Local Calendar System

Published

2007-02-09

·

Updated

2024-08-07

·

CVE-2007-0860

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: local Calendar System version 1.1
Description: The issue allows remote attackers to execute arbitrary PHP code via a URL in the TEMPLATE DIR parameter to files such as showinvoices.php, showmonth.php, showevents.php, retrieveinvoice.php, modifyitem.php, and lookup userid.php; or the LIBDIR parameter to files like editevent.php, resetpassword.php, signup.php, showmonth.php, showday.php, showevents.php, and lookup userid.php. A third party has disputed this issue, stating that the associated variables are set in config.php before use.
Recommendations: For local Calendar System version 1.1, as a temporary workaround, consider restricting access to the TEMPLATE DIR and LIBDIR parameters in the affected files until a patch is available. Avoid using the TEMPLATE DIR parameter in the affected API endpoints, such as /showinvoices.php, /showmonth.php, /showevents.php, /retrieveinvoice.php, /modifyitem.php, and /lookup userid.php, and the LIBDIR parameter in /editevent.php, /resetpassword.php, /signup.php, /showmonth.php, /showday.php, /showevents.php, and /lookup userid.php, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2007-0860

Affected Products

Local Calendar System