High
CVSS 7.5
Overview
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP s...
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
This vulnerability is rated 🟠 HIGH.
Recommended actions: