The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2003-0728 | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T02:05:12.304Z
Reserved: 2003-09-03T00:00:00
Link: CVE-2003-0737
No data.
Status : Deferred
Published: 2003-10-20T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2003-0737
No data.
OpenCVE Enrichment
No data.
EUVD