Vulnerability Name: | CVE-2007-1483 (CCN-33008) | ||||||||
Assigned: | 2007-03-15 | ||||||||
Published: | 2007-03-15 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
6.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Mar 15 2007 - 14:48:13 CDT WebCalendar v0.9.45 (13 Dec 2004) (login.php) Remote File include Source: MITRE Type: CNA CVE-2007-1483 Source: SREASON Type: Exploit 2425 Source: MLIST Type: UNKNOWN [webcalendar-announce] 20070304 Announce: Release 1.0.5 (security patch) Source: CCN Type: SourceForge Web page SourceForge.net:Downloading Source: CCN Type: WebCalendar Web page WebCalendar Source: CCN Type: OSVDB ID: 35045 WebCalendar login.php includedir Parameter Remote File Inclusion Source: CCN Type: OSVDB ID: 35046 WebCalendar get_reminders.php includedir Parameter Remote File Inclusion Source: CCN Type: OSVDB ID: 35047 WebCalendar get_events.php includedir Parameter Remote File Inclusion Source: CCN Type: OSVDB ID: 46500 WebCalendar send_reminders.php Multiple Parameter Remote File Inclusion Source: BUGTRAQ Type: UNKNOWN 20070315 WebCalendar v0.9.45 (13 Dec 2004) (login.php) Remote File include Source: BUGTRAQ Type: UNKNOWN 20070320 Re: WebCalendar v0.9.45 (13 Dec 2004) (login.php) Remote File include Source: BID Type: Exploit, Patch 23054 Source: CCN Type: BID-23054 WebCalendar IncludeDir Multiple Remote File Include Vulnerabilities Source: XF Type: UNKNOWN webcalendar-multiple-file-include(33008) Source: XF Type: UNKNOWN webcalendar-multiple-file-include(33008) Source: EXPLOIT-DB Type: UNKNOWN 3492 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |