Описание
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-1922
- http://pridels0.blogspot.com/2006/04/totalcalendar-remote-code-execution.html
- http://secunia.com/advisories/19730
- http://sweetphp.com/files/downloads/patches/TotalCalendar/Security_Patch.zip
- http://www.osvdb.org/24748
- http://www.osvdb.org/24751
- http://www.securityfocus.com/bid/17618
- http://www.vupen.com/english/advisories/2006/1418
EPSS
Процентиль: 93%
0.11677
Средний
CVE ID
Связанные уязвимости
nvd
почти 20 лет назад
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
EPSS
Процентиль: 93%
0.11677
Средний