CVE-2002-2065

WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:webcalendar:webcalendar:0.9.31:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar:webcalendar:0.9.32:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar:webcalendar:0.9.33:*:*:*:*:*:*:*
cpe:2.3:a:webcalendar:webcalendar:0.9.34:*:*:*:*:*:*:*

History

20 Nov 2024, 23:42

Type Values Removed Values Added
References () http://sourceforge.net/project/shownotes.php?group_id=3870&release_id=93295 - Patch () http://sourceforge.net/project/shownotes.php?group_id=3870&release_id=93295 - Patch
References () http://www.iss.net/security_center/static/9296.php - () http://www.iss.net/security_center/static/9296.php -
References () http://www.securityfocus.com/bid/4961 - () http://www.securityfocus.com/bid/4961 -

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:42


NVD link : CVE-2002-2065

Mitre link : CVE-2002-2065

CVE.ORG link : CVE-2002-2065


JSON object : View

Products Affected

webcalendar

  • webcalendar