Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Calendarix 远程攻击漏洞
Vulnerability Description
Calendarix中存在远程攻击漏洞。远程攻击者借助提交到calendar.php的(1)无效的month[]参数、到cal_week.php的(2)无效的catview[]参数、到yearcal.php的(3)无效的ycyear[]参数或对cal_functions.inc.php的(4)直接请求,获得敏感信息。这会在不同的错误信息中显示安装路径。
CVSS Information
N/A
Vulnerability Type
N/A