Описание
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-7055
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25878
- https://www.exploit-db.com/exploits/1753
- http://securityreason.com/securityalert/2290
- http://sweetphp.com/files/downloads/patches/TotalCalendar/Security_Patch.zip
- http://sweetphp.com/nuke/index.php
- http://www.osvdb.org/25237
- http://www.securityfocus.com/archive/1/431866/30/5370/threaded
- http://www.securityfocus.com/bid/17618
EPSS
Процентиль: 95%
0.19447
Средний
CVE ID
Связанные уязвимости
nvd
почти 19 лет назад
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
EPSS
Процентиль: 95%
0.19447
Средний