Back

CVE-2006-0206

Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.

Published: Jan 13, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
light_weight_calendar light_weight_calendar 1.0

GitHub Security Advisory GHSA-m58g-r4fm-54mc

Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 4.28%

Top 10% most likely to be exploited

Threat Score 31.3 / 100

Data Sources

NVD EPSS GitHub