This application requires Javascript for optimal performance.

ACal.Arbitrary.Command.Execution

Release Date

Mar 14, 2007

Severity

low

Impact

The execution of arbitrary PHP code on the system.

Description

It indicates a possible exploit of a PHP remote file inclusion vulnerability in ACal.

This flaw is due to an input validation error in the "embed/day.php" script that does not validate the "path" parameter.

Affected Products

ACal ACal 2.2.6
ACal ACal 2.2.5
ACal ACal 2.2.4

Recommended Actions

Currently we are not aware of any official supplied fix for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-2261

Reference/s

http://www.frsirt.com/english/advisories/2006/1692 (FrSIRT)
http://www.securityfocus.com/bid/17886 (BugTraq)

Reference: VID-14343