PT-2007-2538 · Activecalendar · Activecalendar

Simon Bonnard

·

Published

2007-02-26

·

Updated

2018-10-16

·

CVE-2007-1110

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ActiveCalendar version 1.2.0
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using a .. (dot dot) in the page parameter of the /data/showcode.php endpoint.
Recommendations For ActiveCalendar version 1.2.0, consider restricting access to the /data/showcode.php endpoint until a patch is available. As a temporary workaround, avoid using the page parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1110

Affected Products

Activecalendar