← All CVEs

CVE-2004-1423

high · 7.5

Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.

7.5
CVSS
15.5%
EPSS (exploit prob.)
97th
EPSS percentile
2004-12-31
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
php-calendarphp-calendar<= 0.10
php-calendarphp-calendar0.1
php-calendarphp-calendar0.2
php-calendarphp-calendar0.3
php-calendarphp-calendar0.4
php-calendarphp-calendar0.5
php-calendarphp-calendar0.6
php-calendarphp-calendar0.7
php-calendarphp-calendar0.8
php-calendarphp-calendar0.9
php-calendarphp-calendar0.9.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-1423