PHPEventCalendar Remote Command Execution Vulnerability
BID:5021
Info
PHPEventCalendar Remote Command Execution Vulnerability
| Bugtraq ID: | 5021 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2002 12:00AM |
| Updated: | Jun 14 2002 12:00AM |
| Credit: | Vulnerability first detailed in the project changelog. |
| Vulnerable: |
WesMo phpEventCalendar 1.1 |
| Not Vulnerable: |
WesMo phpEventCalendar 1.2 |
Discussion
PHPEventCalendar Remote Command Execution Vulnerability
A vulnerability has been reported in phpEventCalendar that may allow a user of phpEventCalendar to execute commands on a vulnerable host.
User supplied values are not properly sanitized.
Commands executed via this method will be executed with the privileges of the user running the web server process. This could potentially lead to a denial of service, or a remote attacker gaining elevated privileges.
A vulnerability has been reported in phpEventCalendar that may allow a user of phpEventCalendar to execute commands on a vulnerable host.
User supplied values are not properly sanitized.
Commands executed via this method will be executed with the privileges of the user running the web server process. This could potentially lead to a denial of service, or a remote attacker gaining elevated privileges.
Exploit / POC
PHPEventCalendar Remote Command Execution Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
PHPEventCalendar Remote Command Execution Vulnerability
Solution:
An updated version is available.
WesMo phpEventCalendar 1.1
Solution:
An updated version is available.
WesMo phpEventCalendar 1.1
-
WesMo phpEventCalendar-1.2.tar.gz
http://www.wesmo.com/~rwest/phpEventCalendar/phpEventCalendar-1.2.tar. gz