{ "schema_version": "1.4.0", "id": "GHSA-cm6r-5gc3-m2wj", "modified": "2022-05-01T18:44:09Z", "published": "2022-05-01T18:44:09Z", "aliases": [ "CVE-2007-6553" ], "details": "Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONF[app_root] parameter to (1) tcuser.class.php, (2) absencecount.inc.php, (3) avatar.inc.php, (4) csvhandler.class.php, (5) functions.tcpro.php, (6) header.html.inc.php, (7) joomlajack.tcpro.php, (8) menu.inc.php, (9) other.inc.php, (10) tcabsence.class.php, (11) tcabsencegroup.class.php, (12) tcallowance.class.php, (13) tcannouncement.class.php, (14) tcconfig.class.php, (15) tcdaynote.class.php, (16) tcgroup.class.php, (17) tcholiday.class.php, (18) tclogin.class.php, (19) tcmonth.class.php, (20) tctemplate.class.php, (21) tcusergroup.class.php, or (22) tcuseroption.class.php in includes/, possibly a related issue to CVE-2006-4845.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-6553" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39212" }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/4785" }, { "type": "WEB", "url": "http://osvdb.org/39805" }, { "type": "WEB", "url": "http://osvdb.org/39806" }, { "type": "WEB", "url": "http://osvdb.org/39807" }, { "type": "WEB", "url": "http://osvdb.org/39808" }, { "type": "WEB", "url": "http://osvdb.org/39809" }, { "type": "WEB", "url": "http://osvdb.org/39810" }, { "type": "WEB", "url": "http://osvdb.org/39811" }, { "type": "WEB", "url": "http://osvdb.org/39812" }, { "type": "WEB", "url": "http://osvdb.org/39813" }, { "type": "WEB", "url": "http://osvdb.org/39814" }, { "type": "WEB", "url": "http://osvdb.org/39815" }, { "type": "WEB", "url": "http://osvdb.org/39816" }, { "type": "WEB", "url": "http://osvdb.org/39817" }, { "type": "WEB", "url": "http://osvdb.org/39818" }, { "type": "WEB", "url": "http://osvdb.org/39819" }, { "type": "WEB", "url": "http://osvdb.org/39820" }, { "type": "WEB", "url": "http://osvdb.org/39821" }, { "type": "WEB", "url": "http://osvdb.org/39822" }, { "type": "WEB", "url": "http://osvdb.org/39823" }, { "type": "WEB", "url": "http://osvdb.org/39824" }, { "type": "WEB", "url": "http://osvdb.org/39825" }, { "type": "WEB", "url": "http://osvdb.org/39826" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/27022" } ], "database_specific": { "cwe_ids": [ "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-12-28T00:46:00Z" } }