MEDIUM
PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter, which is remotely accessed in an fopen call whose results are used to define a user_inc setting that is used in an include_once call
Published Jun 2, 2006
6.4
MEDIUMCVSS 2.0
EPSS 2.17%
Description
Affected products
Remediation
References (10)
Change history (0)
No recorded changes yet.