6.8
CVSSv2

CVE-2005-3366

Published: 30/10/2005 Updated: 11/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 up to and including 2.0.1 allows remote malicious users to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher.

Vulnerable Product Search on Vulmon Subscribe to Product

php icalendar php icalendar 2.0.1

php icalendar php icalendar 2.0a2

php icalendar php icalendar 2.0b

php icalendar php icalendar 2.0c