Search

published date: December 31, 2004

CVE-2004-1423 : Multiple PHP remote file...

Description

Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.

Product(s):

  • PHP-Calendar PHP-Calendar
  • PHP-Calendar PHP-Calendar 0.10
  • PHP-Calendar PHP-Calendar 0.1
  • PHP-Calendar PHP-Calendar 0.2
  • PHP-Calendar PHP-Calendar 0.3

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-1423, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-1423 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?