5
CVE-2006-1292
- EPSS 2.78%
- Veröffentlicht 19.03.2006 23:02:00
- Zuletzt bearbeitet 16.06.2026 22:22:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php Icalendar ≫ Php Icalendar Version <= 2.2.1
Php Icalendar ≫ Php Icalendar Version2.0
Php Icalendar ≫ Php Icalendar Version2.0.1
Php Icalendar ≫ Php Icalendar Version2.0a2
Php Icalendar ≫ Php Icalendar Version2.0b
Php Icalendar ≫ Php Icalendar Version2.0c
Php Icalendar ≫ Php Icalendar Version2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.78% | 0.845 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/19285
http://www.vupen.com/english/advisories/2006/1019
http://www.securityfocus.com/bid/17125
https://www.exploit-db.com/exploits/1585