Security Advisory

CVE-2004-1423

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2005-02-12 05:00:00
Last updated 2024-08-08 00:53:23
Assigner mitre
State PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.