CVE-2006-4458

Publication date 31 August 2006

Last updated 17 July 2025


Ubuntu priority

Description

Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the GLOBALS[phpgw_info][user][preferences][common][country] parameter.

Status

Package Ubuntu Release Status
phpgroupware 9.10 karmic
Fixed 0.9.16.011-2
9.04 jaunty
Fixed 0.9.16.011-2
8.10 intrepid
Fixed 0.9.16.011-2
8.04 LTS hardy
Fixed 0.9.16.011-2
7.10 gutsy
Fixed 0.9.16.011-2
7.04 feisty
Fixed 0.9.16.011-2
6.10 edgy
Fixed 0.9.16.011-2
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities