7.5

CVE-2008-5967

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpicalendarPhpicalendar Version <= 2.3.4
PhpicalendarPhpicalendar Version0.7
PhpicalendarPhpicalendar Version0.8
PhpicalendarPhpicalendar Version0.9
PhpicalendarPhpicalendar Version0.9.5
PhpicalendarPhpicalendar Version1.0
PhpicalendarPhpicalendar Version1.1
PhpicalendarPhpicalendar Version2.0 Updatebeta
PhpicalendarPhpicalendar Version2.0.1
PhpicalendarPhpicalendar Version2.0c
PhpicalendarPhpicalendar Version2.1
PhpicalendarPhpicalendar Version2.2
PhpicalendarPhpicalendar Version2.21
PhpicalendarPhpicalendar Version2.22
PhpicalendarPhpicalendar Version2.23
PhpicalendarPhpicalendar Version2.23 Updaterc1
PhpicalendarPhpicalendar Version2.24
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.78% 0.877
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.