Описание
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-7055
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25878
- https://www.exploit-db.com/exploits/1753
- http://securityreason.com/securityalert/2290
- http://sweetphp.com/files/downloads/patches/TotalCalendar/Security_Patch.zip
- http://sweetphp.com/nuke/index.php
- http://www.osvdb.org/25237
- http://www.securityfocus.com/archive/1/431866/30/5370/threaded
- http://www.securityfocus.com/bid/17618
EPSS
Процентиль: 92%
0.05575
Низкий
CVE ID
Связанные уязвимости
nvd
больше 19 лет назад
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
EPSS
Процентиль: 92%
0.05575
Низкий