CVE-2006-0206

Light Weight Calendar (LWC) <1.0 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-0206.

AI-analyzed exploit summary This Perl script exploits a command injection vulnerability in Light Weight Calendar 1.* by sending a crafted HTTP request with a 'passthru' function call, allowing remote command execution. The exploit uses LWP::Simple to interact with the target and includes a loop for repeated command execution.

Description

Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.

Exploits (1)

exploitdb WORKING POC
perlwebappsphp
https://www.exploit-db.com/exploits/1570

This Perl script exploits a command injection vulnerability in Light Weight Calendar 1.* by sending a crafted HTTP request with a 'passthru' function call, allowing remote command execution. The exploit uses LWP::Simple to interact with the target and includes a loop for repeated command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Light Weight Calendar 1.*
No auth needed
Prerequisites: Network access to the target web application · Light Weight Calendar 1.* installed and accessible
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit x_refsource_misc
http://evuln.com/vulns/29/exploit.html
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18450
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16229
Various Sources mailing-list x_refsource_vim
http://attrition.org/pipermail/vim/2006-March/000612.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24110
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/22376
Exploit, Vendor Advisory x_refsource_misc
http://evuln.com/vulns/29/summary.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0171
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/421920

Scores

EPSS 0.1025
EPSS Percentile 93.3%

Details

Status published
Products (1)
light_weight_calendar/light_weight_calendar 1.0
Published Jan 13, 2006
Tracked Since Feb 18, 2026