Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

aspWebCalendar 'calendar_admin.asp' Arbitrary File Upload Vulnerability

aspWebCalendar is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issue occurs because the application fails to sanitize user-supplied input.

Versions prior to aspWebCalendar 4.5.3c are vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus