CVE-2007-6553

N/A Unknown
Published: December 28, 2007 Modified: April 23, 2026
View on NVD

Description

Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONF[app_root] parameter to (1) tcuser.class.php, (2) absencecount.inc.php, (3) avatar.inc.php, (4) csvhandler.class.php, (5) functions.tcpro.php, (6) header.html.inc.php, (7) joomlajack.tcpro.php, (8) menu.inc.php, (9) other.inc.php, (10) tcabsence.class.php, (11) tcabsencegroup.class.php, (12) tcallowance.class.php, (13) tcannouncement.class.php, (14) tcconfig.class.php, (15) tcdaynote.class.php, (16) tcgroup.class.php, (17) tcholiday.class.php, (18) tclogin.class.php, (19) tcmonth.class.php, (20) tctemplate.class.php, (21) tcusergroup.class.php, or (22) tcuseroption.class.php in includes/, possibly a related issue to CVE-2006-4845.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/39805
Source: cve@mitre.org
http://osvdb.org/39806
Source: cve@mitre.org
http://osvdb.org/39807
Source: cve@mitre.org
http://osvdb.org/39808
Source: cve@mitre.org
http://osvdb.org/39809
Source: cve@mitre.org
http://osvdb.org/39810
Source: cve@mitre.org
http://osvdb.org/39811
Source: cve@mitre.org
http://osvdb.org/39812
Source: cve@mitre.org
http://osvdb.org/39813
Source: cve@mitre.org
http://osvdb.org/39814
Source: cve@mitre.org
http://osvdb.org/39815
Source: cve@mitre.org
http://osvdb.org/39816
Source: cve@mitre.org
http://osvdb.org/39817
Source: cve@mitre.org
http://osvdb.org/39818
Source: cve@mitre.org
http://osvdb.org/39819
Source: cve@mitre.org
http://osvdb.org/39820
Source: cve@mitre.org
http://osvdb.org/39821
Source: cve@mitre.org
http://osvdb.org/39822
Source: cve@mitre.org
http://osvdb.org/39823
Source: cve@mitre.org
http://osvdb.org/39824
Source: cve@mitre.org
http://osvdb.org/39825
Source: cve@mitre.org
http://osvdb.org/39826
Source: cve@mitre.org
http://www.securityfocus.com/bid/27022
Source: cve@mitre.org
Exploit
http://osvdb.org/39805
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39806
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39807
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39808
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39809
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39810
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39811
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39812
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39813
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39814
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39815
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39816
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39817
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39818
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39819
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39820
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39821
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39822
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39823
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39824
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39825
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/39826
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/27022
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/39212
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/4785
Source: af854a3a-2127-422b-91ae-364da2661108

50 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
3.7%
88th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

george_lewe