WebCalendar 0.9.34 and earlier with browsing in includes directory enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webcalendar | Webcalendar | 0.9.31 (including) | 0.9.31 (including) |
Webcalendar | Webcalendar | 0.9.32 (including) | 0.9.32 (including) |
Webcalendar | Webcalendar | 0.9.33 (including) | 0.9.33 (including) |
Webcalendar | Webcalendar | 0.9.34 (including) | 0.9.34 (including) |