PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[CLPath] parameter to (1) reconfig.php and (2) srxclr.php. NOTE: this might be due to a globals overwrite issue.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Calogic_calendars | Calogic | 1.2.2 (including) | 1.2.2 (including) |