Required CVE Record Information
Description
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.
References 12 Total
- securitytracker.com: 1017107 vdb-entry
- securityfocus.com: 12127 vdb-entry
- http://www.gulftech.org/?node=research&article_id=00060-12292004
- http://sourceforge.net/project/shownotes.php?release_id=296020&group_id=46800
- vupen.com: ADV-2006-4145 vdb-entry
- marc.info: 20041229 php-Calendar File Include Vulnerability [ Command Exec ] mailing-list
- exploit-db.com: 2608 exploit
- securityfocus.com: 20657 vdb-entry
- exchange.xforce.ibmcloud.com: vlo-phpcrootpath-file-include(29710) vdb-entry
- securityfocus.com: 20061021 Virtual Law Office (phpc_root_path) Remote File Include Vulnerability mailing-list
- secunia.com: 22516 third-party-advisory
- exchange.xforce.ibmcloud.com: php-calendar-file-include(18710) vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 12 Total
- securitytracker.com: 1017107 vdb-entryx_transferred
- securityfocus.com: 12127 vdb-entryx_transferred
- http://www.gulftech.org/?node=research&article_id=00060-12292004 x_transferred
- http://sourceforge.net/project/shownotes.php?release_id=296020&group_id=46800 x_transferred
- vupen.com: ADV-2006-4145 vdb-entryx_transferred
- marc.info: 20041229 php-Calendar File Include Vulnerability [ Command Exec ] mailing-listx_transferred
- exploit-db.com: 2608 exploitx_transferred
- securityfocus.com: 20657 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: vlo-phpcrootpath-file-include(29710) vdb-entryx_transferred
- securityfocus.com: 20061021 Virtual Law Office (phpc_root_path) Remote File Include Vulnerability mailing-listx_transferred
- secunia.com: 22516 third-party-advisoryx_transferred
- exchange.xforce.ibmcloud.com: php-calendar-file-include(18710) vdb-entryx_transferred