5

CVE-2006-0648

Exploit
Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php IcalendarPhp Icalendar Version2.0
Php IcalendarPhp Icalendar Version2.0.1
Php IcalendarPhp Icalendar Version2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.07% 0.789
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://evuln.com/vulns/70/summary.html
Patch
Vendor Advisory
Exploit
http://phpicalendar.net/forums/viewtopic.php?t=396
http://secunia.com/advisories/18778
Patch
Vendor Advisory
http://securityreason.com/securityalert/420
http://www.securityfocus.com/archive/1/424424/100/0/threaded
http://www.securityfocus.com/bid/16557
http://www.vupen.com/english/advisories/2006/0493
https://exchange.xforce.ibmcloud.com/vulnerabilities/24591