Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the GLOBALS[phpgw_info][user][preferences][common][country] parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PhpGroupWare日历模块'class.holidaycalc.inc.php'路径遍历漏洞
Vulnerability Description
phpGroupWare是一个用PHP编写的多用户的网络组件,为开发其他程序提供了一个API。 phpGroupWare在处理用户请求时存在输入验证,远程攻击者可能利用此漏洞在服务器上以Web进程权限执行任意命令。 phpGroupWare的calendar/inc/class.holidaycalc.inc.php脚本没有正确验证全局phpgw_info[user][preferences][common][country]参数的输入,存在路径遍历漏洞。远程攻击者可以通过包含本地资源的任意文件导致执行任
CVSS Information
N/A
Vulnerability Type
N/A