Vulnerabilities > CVE-2005-2717 - Remote File Include vulnerability in Webcalendar 1.0.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
webcalendar
nessus

Summary

PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts.

Vulnerable Configurations

Part Description Count
Application
Webcalendar
4

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-799.NASL
    descriptionA trivially-exploitable bug was discovered in webcalendar that allows an attacker to execute arbitrary code with the privileges of the HTTP daemon on a system running a vulnerable version.
    last seen2020-06-01
    modified2020-06-02
    plugin id19569
    published2005-09-06
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19569
    titleDebian DSA-799-1 : webcalendar - remote code execution
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_60F8FE7B3CFB11DABAA20004614CC33D.NASL
    descriptionWebCalendar is proven vulnerable to a remote file inclusion vulnerability. The send_reminders.php does not properly verify the
    last seen2020-06-01
    modified2020-06-02
    plugin id21436
    published2006-05-13
    reporterThis script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/21436
    titleFreeBSD : WebCalendar -- remote file inclusion vulnerability (60f8fe7b-3cfb-11da-baa2-0004614cc33d)
  • NASL familyCGI abuses
    NASL idWEBCALENDAR_INCLUDEDIR_FILE_INCLUDES.NASL
    descriptionThe remote version of WebCalendar fails to sanitize user-supplied input to the
    last seen2020-06-01
    modified2020-06-02
    plugin id19502
    published2005-08-25
    reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/19502
    titleWebCalendar send_reminders.php includedir Parameter Remote File Inclusion