CVE Vulnerabilities

CVE-2006-1292

Published: Mar 19, 2006 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.

Affected Software

Name Vendor Start Version End Version
Php_icalendar Php_icalendar 2.0b 2.0b
Php_icalendar Php_icalendar 2.0 2.0
Php_icalendar Php_icalendar 2.0a2 2.0a2
Php_icalendar Php_icalendar 2.0.1 2.0.1
Php_icalendar Php_icalendar * 2.2.1
Php_icalendar Php_icalendar 2.1 2.1
Php_icalendar Php_icalendar 2.0c 2.0c

References