"evaluatorSolution":"Upgrade to phpGroupWare 0.9.16.011",
"descriptions":[
{
"lang":"en",
"value":"Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the GLOBALS[phpgw_info][user][preferences][common][country] parameter."
},
{
"lang":"es",
"value":"Vulnerabilidad de directorio transversal en calendar/inc/class.holidaycalc.inc.php en phpGroupWare 0.9.16.010 y anteriores permite a un atacante remoto incluir archivos loccales de su elecci\u00f3n a trav\u00e9s de la secuencia .. (punto punto) y el byte nulo de acarreo (%00) en el par\u00e1metro GLOBALS[phpgw_info][user][preferences][common][country] ."