This application requires Javascript for optimal performance.

PHP.showcode.php.PAGE.Parameter.File.Inclusion

Release Date

Apr 15, 2008

Severity

medium

Impact

System Compromise.

Description

This indicates an attempt to exploit a PHP remote file inclusion vulnerability in ActiveCalendar.

The vulnerability is due to an input validation error in the "data/showcode.php" script. The script does not validate the "page" parameter before it is passed to an "fread()" call. This can be exploited by remote attackers to disclose the contents of arbitrary files.

Affected Products

Active Calendar 1.2

Recommended Actions

Apply the latest update from the vendor:
http://www.micronetwork.de/activecalendar/.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-1110

Reference/s

http://www.frsirt.com/english/advisories/2007/0759 (FrSIRT)
http://www.securityfocus.com/bid/22704 (BugTraq)

Reference: VID-15546