PublicDate: 2006-06-02 01:02:00 UTC Candidate: CVE-2006-2762 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2762 Description: PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter, which is remotely accessed in an fopen call whose results are used to define a user_inc setting that is used in an include_once call. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_webcalendar: ignored (reached end-of-life) edgy_webcalendar: released (1.0.4-1) feisty_webcalendar: DNE gutsy_webcalendar: released (1.0.4-1) hardy_webcalendar: released (1.0.4-1) intrepid_webcalendar: released (1.0.4-1) jaunty_webcalendar: released (1.0.4-1) karmic_webcalendar: released (1.0.4-1) devel_webcalendar: released (1.0.4-1) upstream_webcalendar: needs-triage