HIGH
Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via a full pathname in the configfile parameter to (1) update08.php or (2) update10.php
Published Dec 22, 2009
7.5
HIGHCVSS 2.0
EPSS 2.45%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.