Unrated severityNVD Advisory· Published Apr 20, 2006· Updated Apr 16, 2026
CVE-2006-1922
CVE-2006-1922
Description
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
Affected products
3cpe:2.3:a:sweetphp:totalcalendar:2.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sweetphp:totalcalendar:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:sweetphp:totalcalendar:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:sweetphp:totalcalendar:2.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/19730nvdVendor Advisory
- pridels0.blogspot.com/2006/04/totalcalendar-remote-code-execution.htmlnvd
- sweetphp.com/files/downloads/patches/TotalCalendar/Security_Patch.zipnvd
- www.osvdb.org/24748nvd
- www.osvdb.org/24751nvd
- www.securityfocus.com/bid/17618nvd
- www.vupen.com/english/advisories/2006/1418nvd
News mentions
0No linked articles in our index yet.