CVE Vulnerabilities

CVE-2006-1292

Published: Mar 19, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.

Affected Software

Name Vendor Start Version End Version
Php_icalendar Php_icalendar * 2.2.1 (including)
Php_icalendar Php_icalendar 2.0 (including) 2.0 (including)
Php_icalendar Php_icalendar 2.0.1 (including) 2.0.1 (including)
Php_icalendar Php_icalendar 2.0a2 (including) 2.0a2 (including)
Php_icalendar Php_icalendar 2.0b (including) 2.0b (including)
Php_icalendar Php_icalendar 2.0c (including) 2.0c (including)
Php_icalendar Php_icalendar 2.1 (including) 2.1 (including)

References