Loading...
Loading...
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.
January 26, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-5967
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.