WebCalendar Remote Command Execution Vulnerability
BID:2639
Info
WebCalendar Remote Command Execution Vulnerability
| Bugtraq ID: | 2639 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0477 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Discovered by Secure Reality Pty Ltd. and published in an advisory to Bugtraq on April 23, 2001. |
| Vulnerable: |
WebCalendar WebCalendar 0.9.24 WebCalendar WebCalendar 0.9.15 k5n WebCalendar 0.9.26 k5n WebCalendar 0.9.25 k5n WebCalendar 0.9.23 k5n WebCalendar 0.9.22 k5n WebCalendar 0.9.21 k5n WebCalendar 0.9.20 k5n WebCalendar 0.9.19 k5n WebCalendar 0.9.16 k5n WebCalendar 0.9.11 k5n WebCalendar 0.9.8 |
| Not Vulnerable: | |
Discussion
WebCalendar Remote Command Execution Vulnerability
WebCalendar is a freely available PHP web application used to maintain a calendar for one or more people.
An input validation error exists which could make it possible for a malicious user with a valid WebCalendar account to execute arbitrary commands remotely.
In WebCalendar configurations where "single user mode" is enabled (though not found by default), this vulnerability may be exploited by unauthenticated remote users.
WebCalendar is a freely available PHP web application used to maintain a calendar for one or more people.
An input validation error exists which could make it possible for a malicious user with a valid WebCalendar account to execute arbitrary commands remotely.
In WebCalendar configurations where "single user mode" is enabled (though not found by default), this vulnerability may be exploited by unauthenticated remote users.
Exploit / POC
WebCalendar Remote Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WebCalendar Remote Command Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
k5n WebCalendar 0.9.26
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
k5n WebCalendar 0.9.26
-
Secure Reality WebCalendar-SecureReality.diff
http://www.securereality.com.au/patches/WebCalendar-SecureReality.diff
References
WebCalendar Remote Command Execution Vulnerability
References:
References:
- SourceForge WebCalendar Development Homepage (Craig Knudsen)