CVE-2006-2570
CaLogic Calendars 1.2.2 - Remote File Inclusion via GLOBALS[CLPath] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2570. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in CaLogic Calendars V1.2.2 by manipulating the `GLOBALS[CLPath]` parameter in `reconfig.php` and `srxclr.php` to include arbitrary remote scripts.
Description
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLPath"] parameter to (1) reconfig.php and (2) srxclr.php. NOTE: this might be due to a globals overwrite issue.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in CaLogic Calendars V1.2.2 by manipulating the `GLOBALS[CLPath]` parameter in `reconfig.php` and `srxclr.php` to include arbitrary remote scripts.