7.5

CVE-2008-5840

Exploit
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpicalendarPhpicalendar Version <= 2.24
PhpicalendarPhpicalendar Version0.7
PhpicalendarPhpicalendar Version0.8
PhpicalendarPhpicalendar Version0.9
PhpicalendarPhpicalendar Version0.9.5
PhpicalendarPhpicalendar Version1.0
PhpicalendarPhpicalendar Version1.1
PhpicalendarPhpicalendar Version2.0 Updatebeta
PhpicalendarPhpicalendar Version2.0.1
PhpicalendarPhpicalendar Version2.0c
PhpicalendarPhpicalendar Version2.1
PhpicalendarPhpicalendar Version2.2
PhpicalendarPhpicalendar Version2.21
PhpicalendarPhpicalendar Version2.22
PhpicalendarPhpicalendar Version2.23
PhpicalendarPhpicalendar Version2.23 Updaterc1
PhpicalendarPhpicalendar2.0 Versionalpha_test
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.02% 0.857
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securityreason.com/securityalert/4865
http://www.securityfocus.com/bid/31320
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/45338
https://www.exploit-db.com/exploits/6526