7.5
CVSSv2

CVE-2008-5840

Published: 05/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP iCalendar 2.24 and previous versions allows remote malicious users to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpicalendar phpicalendar 2.23

phpicalendar phpicalendar 2.0

phpicalendar phpicalendar2.0 alpha_test

phpicalendar phpicalendar 2.2

phpicalendar phpicalendar 2.1

phpicalendar phpicalendar 0.9.5

phpicalendar phpicalendar 0.9

phpicalendar phpicalendar 2.22

phpicalendar phpicalendar 2.21

phpicalendar phpicalendar 1.1

phpicalendar phpicalendar 1.0

phpicalendar phpicalendar

phpicalendar phpicalendar 2.0.1

phpicalendar phpicalendar 2.0c

phpicalendar phpicalendar 0.8

phpicalendar phpicalendar 0.7

Exploits

############################################################################################### [+] PHP iCalendar <= 224 Insecure Cookie Handling Vulnerability [+] Discovered By Stack [+] Greetz : All my freind ################################################################################################ --- exp ...