PHP ICalendar Template.PHP Remote File Include Vulnerability
BID:16557
Info
PHP ICalendar Template.PHP Remote File Include Vulnerability
| Bugtraq ID: | 16557 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2006 12:00AM |
| Updated: | Feb 09 2006 03:58PM |
| Credit: | Aliaksandr Hartsuyeu is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP iCalendar PHP iCalendar 2.0.1 PHP iCalendar PHP iCalendar 2.1 PHP iCalendar PHP iCalendar 2.0 |
| Not Vulnerable: | |
Discussion
PHP ICalendar Template.PHP Remote File Include Vulnerability
PHP iCalendar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
PHP iCalendar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Exploit / POC
PHP ICalendar Template.PHP Remote File Include Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHP ICalendar Template.PHP Remote File Include Vulnerability
Solution:
The vendor has released a patch to resolve these issues; please see the reference section for further details.
Solution:
The vendor has released a patch to resolve these issues; please see the reference section for further details.
References
PHP ICalendar Template.PHP Remote File Include Vulnerability
References:
References:
- **Security Issue in phpicalendar 2.2 and possibly earlier** (PHP iCalendar)
- PHP iCalendar Homepage (PHP iCalendar)
- PHP iCalendar File Inclusion Vulnerability ([email protected])