7.5
CVSSv2

CVE-2007-1343

Published: 08/03/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

includes/functions.php in Craig Knudsen WebCalendar prior to 1.0.5 does not protect the noSet variable from external modification, which allows remote malicious users to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues.

Vulnerable Product Search on Vulmon Subscribe to Product

webcalendar webcalendar 1.0.2

webcalendar webcalendar 1.0.3

webcalendar webcalendar 1.0.0

webcalendar webcalendar 1.0.1

webcalendar webcalendar 1.0.4

Vendor Advisories

It was discovered that WebCalendar, a PHP-based calendar application, insufficiently protects an internal variable, which allows remote file inclusion For the stable distribution (sarge) this problem has been fixed in version 0945-4sarge6 The upcoming stable distribution (etch) no longer contains webcalendar packages For the unstable distribut ...