ACal.Arbitrary.Command.Execution

description-logoDescription

It indicates a possible exploit of a PHP remote file inclusion vulnerability in ACal.
This flaw is due to an input validation error in the "embed/day.php" script that does not validate the "path" parameter.

affected-products-logoAffected Products

ACal ACal 2.2.6
ACal ACal 2.2.5
ACal ACal 2.2.4

Impact logoImpact

The execution of arbitrary PHP code on the system.

recomended-action-logoRecommended Actions

Currently we are not aware of any official supplied fix for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)