what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

PHP-Calendar Information Disclosure

PHP-Calendar Information Disclosure
Posted Feb 6, 2009
Authored by Justin C. Klein Keane

PHP-Calendar suffers from an information disclosure vulnerability due to old update php files being left behind.

tags | advisory, php, info disclosure
SHA-256 | cbdb6e27a0f7e1f710c10c367f22d58f81f830bdca81b9de7ce942d5a228d804

PHP-Calendar Information Disclosure

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Security Risk: Moderate
Exploitable: Remotely
Vulnerability: Information disclosure
Version: Multiple Versions

PHP-Calendar (http://www.php-calendar.com) was "written for a college
social group at Northeastern University to keep track of events, etc. We
were previously using localendar, which I (Sean Proctor) didn't like and
had some problems with. I found CST-Calendar which did most of what I
wanted, but was rather ugly and missed some features that we needed. So,
I gradually re-wrote CST-Calendar since that project seemed to have
stopped work entirely."

This vulnerability centers around the fact that PHP-Calendar comes with
update scripts to update previous versions of the software. These
scripts will print to the screen the database host, username, password,
database name, table prefix, and database type. This file is named in
two separate conventions depending on the installed version of
PHP-Calendar. In versions prior to 1.1 this file is named "update.php"
in version 1.1 two files exist named "update08.php" and "update10.php".
Calling these files via a web browser (e.x.
http://targetsite.com/phpcalendar/update.php) will print a succinct
message including the above described information.

Determinging version of PHP-Calendar is often trivial as a NEWS file is
included in every distribution that will reveal version information.
Browsing to http://targetsite.tld/phpcalendar/NEWS will display the
versioning information if that file is present. Note that several
versions of PHP-Calendar are affected by other vulnerabilities (SQL
injection - http://www.securityfocus.com/bid/13405/, remote file
inclusion - http://www.securityfocus.com/bid/12127/).

Remediation

Removal of the update scripts and all other unnecessary files (AUTHORS,
COPYING, FAQ, INSTALL, NEWS, README, UPDATE) should remedy this
vulnerability. Unfortunately instructions about the removal of these
files is not included in the installation guide or the automated install
scripts.

- --
Justin C. Klein Keane
http://www.MadIrish.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iQD1AwUBSYxeVZEpbGy7DdYAAQLjfgb/dUsoJhEHQt4vO5f0TdRHwvBCgn4a9lQv
OKM/Eg3jLbAVHHLitBJnN8TabGr2DUc+aJYSk62BCY2r8HrLZGsNd9fLkKWNZYKR
BH7CV0LBtRyicP25NVeBPQ133Z7UYpH+cbbAmp+W00OdomPANsQcGtNzwFPuDbXo
lQyGKzgLsKQD1iS+FYifkW5QC0Z5O0RkphInxTR5JGODcSVah3y3l6aWxIl0q2eq
cMWR+qDY2A9fP0VzwlANhLMcgO/XI4ZmAxDKC17g/BkHTEqL/SFwuRcvoocsvcQ3
jcloc+gm+68=
=kWDx
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close