10
CVSSv2

CVE-2008-4673

Published: 22/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote malicious users to execute arbitrary PHP code via a URL in the (1) path[docroot] and (2) component parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

webbiscuits events calendar 1.1

Exploits

######################################################### # # Events Calendar 11 Remote File Inclusion Vulnerability #======================================================== # Author: kevin mitnick( tunisianblackhat team ) = # = # Home : tunisianblackhatcom = # = # email: kevinmitnick[A]livefr = # = #================================== ...