CVE-2008-5967
26.01.2009, 20:30
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.Enginsight
Vendor | Product | Version |
---|---|---|
phpicalendar | phpicalendar | 𝑥 ≤ 2.3.4 |
phpicalendar | phpicalendar | 0.7 |
phpicalendar | phpicalendar | 0.8 |
phpicalendar | phpicalendar | 0.9 |
phpicalendar | phpicalendar | 0.9.5 |
phpicalendar | phpicalendar | 1.0 |
phpicalendar | phpicalendar | 1.1 |
phpicalendar | phpicalendar | 2.0:beta |
phpicalendar | phpicalendar | 2.0.1 |
phpicalendar | phpicalendar | 2.0c:c |
phpicalendar | phpicalendar | 2.1 |
phpicalendar | phpicalendar | 2.2 |
phpicalendar | phpicalendar | 2.21 |
phpicalendar | phpicalendar | 2.22 |
phpicalendar | phpicalendar | 2.23 |
phpicalendar | phpicalendar | 2.23:rc1 |
phpicalendar | phpicalendar | 2.24 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration