Vulnerabilities > CVE-2006-3684 - Remote File Include vulnerability in Softcomplex PHP Event Calendar 1.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
PHP remote file inclusion vulnerability in calendar.php in SoftComplex PHP Event Calendar 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_calendar parameter, which overwrites the $path_to_calendar variable from an extract function call.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://secunia.com/advisories/21074
- http://secunia.com/advisories/21417
- http://www.securityfocus.com/archive/1/440265/100/0/threaded
- http://www.securityfocus.com/bid/18965
- http://www.solpotcrew.org/adv/solpot-adv-01.txt
- http://www.vupen.com/english/advisories/2006/2848
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27766