Description
includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1267-1 | New webcalendar packages fix remote file inclusion |
EUVD |
EUVD-2007-1340 | includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:50:35.036Z
Reserved: 2007-03-07T00:00:00.000Z
Link: CVE-2007-1343
No data.
Status : Modified
Published: 2007-03-08T22:19:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-1343
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD