pridels0.blogspot.com
http://pridels0.blogspot.com/2006/04/totalcalendar-remote-code-execution.html CVE-2006-1922
otalCalendar - 'about.php?inc_dir' Remote File Inclusion
Record summary
CVE-2006-1922 has a selected CVSS score of 6.4; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBotalCalendar - 'about.php?inc_dir' Remote File InclusionExploitDB exploitby VietMafiaNot analyzed1 file
References
819730Third-party advisory
http://secunia.com/advisories/19730 sweetphp.com
http://sweetphp.com/files/downloads/patches/TotalCalendar/Security_Patch.zip 24748vdb entry
http://www.osvdb.org/24748 24751vdb entry
http://www.osvdb.org/24751 17618vdb entry
http://www.securityfocus.com/bid/17618 ADV-2006-1418vdb entry
http://www.vupen.com/english/advisories/2006/1418 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-1922