WebCalendar Export_Handler.PHP File Corruption Vulnerability
BID:15608
Info
WebCalendar Export_Handler.PHP File Corruption Vulnerability
| Bugtraq ID: | 15608 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3961 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2005 12:00AM |
| Updated: | Dec 15 2006 09:03PM |
| Credit: | Francesco Ongaro is credited with the discovery of this vulnerability. |
| Vulnerable: |
k5n WebCalendar 1.0.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
WebCalendar Export_Handler.PHP File Corruption Vulnerability
WebCalendar is prone to a file-corruption vulnerability. This is due to a lack of proper validation of user-supplied input.
An attacker may leverage this issue to corrupt files with the privileges of an unsuspecting user running a vulnerable version of the affected application.
Version 1.0.1 is reported to be vulnerable; other versions may also be affected.
WebCalendar is prone to a file-corruption vulnerability. This is due to a lack of proper validation of user-supplied input.
An attacker may leverage this issue to corrupt files with the privileges of an unsuspecting user running a vulnerable version of the affected application.
Version 1.0.1 is reported to be vulnerable; other versions may also be affected.
Exploit / POC
WebCalendar Export_Handler.PHP File Corruption Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
WebCalendar Export_Handler.PHP File Corruption Vulnerability
Solution:
Please see the references for vendor advisories and more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Please see the references for vendor advisories and more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
WebCalendar Export_Handler.PHP File Corruption Vulnerability
References:
References:
- WebCalendar Home Page (WebCalendar)
- WebCalendar Multiple Vulnerabilities (Francesco Ongaro )
- WebCalendar Multiple Vulnerabilities (ascii
)