FreeBSD : phpicalendar -- file disclosure vulnerability (f1f163ce-9e09-11da-b410-000e0c2e438a)

High Nessus Plugin ID 21534


The remote FreeBSD host is missing a security-related update.


The phpicalendar team reports that there is an unspecified vulnerability within phpicalendar. This seems to be a file disclosure vulnerability caused by improper checking of the template parsing function. This would allow an attacker to disclose any file readable by the user under which the webserver runs.


Update the affected package.

See Also

Plugin Details

Severity: High

ID: 21534

File Name: freebsd_pkg_f1f163ce9e0911dab410000e0c2e438a.nasl

Version: $Revision: 1.10 $

Type: local

Published: 2006/05/13

Modified: 2013/08/09

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:phpicalendar, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2006/02/15

Vulnerability Publication Date: 2006/02/08