CVE-2004-1509
Description
validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WebCalendar validate.php reveals full path in error message when given an invalid encoded_login parameter.
Vulnerability
validate.php in WebCalendar contains a vulnerability where an invalid encoded_login parameter triggers an error message that discloses the full installation path of the application. This path disclosure can occur without authentication. The affected versions include WebCalendar 1.0.x and possibly earlier or later versions.
Exploitation
An attacker can exploit this by sending an HTTP request to the vulnerable validate.php script with a crafted encoded_login parameter that is not properly handled, causing PHP to generate an error that includes the full file system path. No authentication or special privileges are required.
Impact
Successful exploitation reveals the full directory path of the WebCalendar installation, which provides an attacker with valuable information that can be used to plan further attacks, such as including files or exploiting local file inclusion vulnerabilities.
Mitigation
No official patch is mentioned in the available references. Users should consider upgrading to a version of WebCalendar that has addressed this issue, or as a workaround, disable or restrict access to validate.php if it is not required. Input validation on the encoded_login parameter should also be implemented.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/11651nvdExploit
- secunia.com/advisories/13164nvdVendor Advisory
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/18029nvd
News mentions
0No linked articles in our index yet.