PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php_icalendar | Php_icalendar | 2.0.1 (including) | 2.0.1 (including) |
Php_icalendar | Php_icalendar | 2.0a2 (including) | 2.0a2 (including) |
Php_icalendar | Php_icalendar | 2.0b (including) | 2.0b (including) |
Php_icalendar | Php_icalendar | 2.0c (including) | 2.0c (including) |