PT-2007-4538 · Calendarix · Calendarix

Published

2007-06-26

·

Updated

2018-10-16

·

CVE-2007-3259

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Calendarix version 0.7.20070307
Description The issue allows remote attackers to obtain sensitive information. This can be achieved through various means, including:
  • an invalid month[] parameter to "calendar.php"
  • an invalid catview[] parameter to "cal week.php" in a week operation
  • an invalid ycyear[] parameter to "yearcal.php"
  • a direct request to "cal functions.inc.php", which reveals the installation path in various error messages.
Recommendations For Calendarix version 0.7.20070307, consider restricting access to the affected scripts until a patch is available. As a temporary workaround, avoid using the parameters month[], catview[], and ycyear[] in the respective API endpoints. Additionally, restrict direct access to "cal functions.inc.php" to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3259

Affected Products

Calendarix