FreeBSD : phpicalendar -- file disclosure vulnerability (f1f163ce-9e09-11da-b410-000e0c2e438a)

high Nessus Plugin ID 21534

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The phpicalendar team reports that there is an unspecified vulnerability within phpicalendar. This seems to be a file disclosure vulnerability caused by improper checking of the template parsing function. This would allow an attacker to disclose any file readable by the user under which the webserver runs.

Solution

Update the affected package.

See Also

http://www.nessus.org/u?47941448

Plugin Details

Severity: High

ID: 21534

File Name: freebsd_pkg_f1f163ce9e0911dab410000e0c2e438a.nasl

Version: 1.13

Type: local

Published: 5/13/2006

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:phpicalendar, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2/15/2006

Vulnerability Publication Date: 2/8/2006