7.5
CVSSv2

CVE-2007-1483

Published: 16/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote malicious users to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php.

Vulnerable Product Search on Vulmon Subscribe to Product

k5n webcalendar 0.9.45

Exploits

|-------------------------------------------------------------------------------| | | | WebCalendar v0945 (13 Dec 2004) (loginphp) Remote File include | | | | Script : WebCalendar | | Version : v0945 (13 Dec 2004) | | Authord : Drackanz | | Contact : Drackanz [at] gmail [] com | | Vendor : wwwk5nus/webcalendarphp | |----------------- ...