7.5
CVSSv2

CVE-2006-6812

Published: 29/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote malicious users to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php.

Vulnerable Product Search on Vulmon Subscribe to Product

myphpcalendar myphpcalendar 10.1

Exploits

# script name : myPHPCalendar # Script Downloads : freshmeatnet/projects/myphpcalendar/ # Web Site : myphpcalendarsourceforgenet/ # Version : 101 # Risk : High # Found By : Cr@zy_King # Thanks : | eTNR | ApAci | Eno7 | TheHacker | Kormali46 | The_Bekir | Metallicali | Liz0zim | ERNE | Swat_Hack | Commander | Soceita # Code ...