CVE-2008-5062
Mini Web Calendar 1.2 - Path Traversal via cal_pdf.php thefile Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5062. PoCs published by ahmadbady.
AI-analyzed exploit summary The exploit demonstrates two vulnerabilities in Mini Web Calendar 1.2: a local file inclusion (LFI) via `cal_pdf.php` and a reflected XSS via `cal_default.php`. Both are trivial to execute and require no authentication.
Description
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory traversal sequences in the thefile parameter.
Exploits (1)
The exploit demonstrates two vulnerabilities in Mini Web Calendar 1.2: a local file inclusion (LFI) via `cal_pdf.php` and a reflected XSS via `cal_default.php`. Both are trivial to execute and require no authentication.