Pages: [1]
|
 |
|
Author
|
Topic: EasyPHPCalendar "serverPath" PHP File Inclusion Vulnerability (Read 481 times)
|
|
Brad
|
* Technical Description * A vulnerability was identified in EasyPHPCalendar, which may be exploited by attackers to compromise a vulnerable web server. This flaw is due to an input validation error when processing a specially crafted "serverPath" variable, which may be exploited by attackers to include arbitrary files and execute remote commands with the privileges of the web server. * Affected Products * EasyPHPCalendar version 6.1.5 and prior * Solution * not aware of any official supplied patch for this issue. * References * http://www.frsirt.com/english/advisories/2005/0959
|
|
|
|
|
Logged
|
|
|
|
|
Pages: [1]
|
|
|
 |