Vulnerabilities > CVE-2006-4060 - Remote File Include vulnerability in Web-Scripts Visual Events Calendar 1.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
web-scripts
exploit available

Summary

PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter.

Vulnerable Configurations

Part Description Count
Application
Web-Scripts
1

Exploit-Db

descriptionVisual Events Calendar 1.1 (cfg_dir) Remote Include Vulnerability. CVE-2006-4060. Webapps exploit for php platform
fileexploits/php/webapps/2141.txt
idEDB-ID:2141
last seen2016-01-31
modified2006-08-07
platformphp
port
published2006-08-07
reporterMehmet Ince
sourcehttps://www.exploit-db.com/download/2141/
titleVisual Events Calendar 1.1 cfg_dir Remote Include Vulnerability
typewebapps