CVE-2007-6553

Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONF[app_root] parameter to (1) tcuser.class.php, (2) absencecount.inc.php, (3) avatar.inc.php, (4) csvhandler.class.php, (5) functions.tcpro.php, (6) header.html.inc.php, (7) joomlajack.tcpro.php, (8) menu.inc.php, (9) other.inc.php, (10) tcabsence.class.php, (11) tcabsencegroup.class.php, (12) tcallowance.class.php, (13) tcannouncement.class.php, (14) tcconfig.class.php, (15) tcdaynote.class.php, (16) tcgroup.class.php, (17) tcholiday.class.php, (18) tclogin.class.php, (19) tcmonth.class.php, (20) tctemplate.class.php, (21) tcusergroup.class.php, or (22) tcuseroption.class.php in includes/, possibly a related issue to CVE-2006-4845.
Configurations

Configuration 1 (hide)

cpe:2.3:a:george_lewe:teamcal_pro:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-12-28 00:46

Updated : 2024-02-04 17:13


NVD link : CVE-2007-6553

Mitre link : CVE-2007-6553

CVE.ORG link : CVE-2007-6553


JSON object : View

Products Affected

george_lewe

  • teamcal_pro
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')