CVE-2006-0183 describes a direct static code injection vulnerability in ACal Calendar Project 2.2.5, allowing authenticated users to execute arbitrary PHP code by modifying header.php or footer.php via the edit.php script. This flaw has a CVSS score of 6.5, indicating a medium severity with network-based attacks, low access complexity, and partial impact on confidentiality, integrity, and availability. While the vulnerability is old and has no known active exploits, public exploit code, or community discussion, its potential for authenticated code execution highlights the risks of insecure administrative functionalities. It's also noted that this issue might be a consequence of a separate authentication bypass vulnerability (CVE-2006-0182).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.5CPE matchmatch criteria | cpe:2.3:a:acal:calendar_project:2.2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.