CVE-2008-5968 |
|
|
Jan 26, 2009 |
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files v
more...
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cookie_language parameter in a phpicalendar_* cookie, a different vector than CVE-2006-1292.
less...
|
2.21, 2.2, 2.1, 2.0.1, 1.1, 1.0, 0.9.5, 0.9, 0.8, 0.7
|
CVE-2008-5967 |
|
|
Jan 26, 2009 |
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote a
more...
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.
less...
|
2.21, 2.2, 2.1, 2.0.1, 1.1, 1.0, 0.9.5, 0.9, 0.8, 0.7
|
CVE-2008-5840 |
|
|
Jan 05, 2009 |
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.
less...
|
2.21, 2.2, 2.1, 2.0.1, 1.1, 1.0, 0.9.5, 0.9, 0.8, 0.7
|
CVE-2006-6824 |
|
|
Dec 29, 2006 |
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbit
more...
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php, (f) rss/index.php, (g) print.php, and (h) preferences.php; the (2) cpath parameter in (i) day.php, (j) month.php, (k) year.php, (l) week.php, and (m) search.php; the (3) query parameter in search.php; and possibly the cpath, (4) unset, and (5) set parameters in a setcookie action in preferences.php; different vectors than CVE-2006-3319. NOTE: it was later reported that vectors b, c, and d also affect 2.24.
less...
|
2.21, 2.2, 2.1, 2.0.1, 1.1, 1.0, 0.9.5, 0.9, 0.8, 0.7
|
CVE-2006-3319 |
|
|
Jun 30, 2006 |
Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or H
more...
Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter.
less...
|
2.21, 2.2, 2.1, 2.0.1, 1.1, 1.0, 0.9.5, 0.9, 0.8, 0.7
|