Php Icalendar is a modestly represented calendar-management application that has been deployed for calendar sharing and scheduling across web environments, with a narrow but persistent vulnerability footprint. Vulnerabilities affecting this vendor center on cross-site scripting and related input-handling weaknesses characteristic of web-facing applications, and the product has acquired public exploit code availability for disclosed issues. Defenders should prioritize patching for this component if it is deployed within their calendar or scheduling infrastructure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Icalendar over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1291HIGH publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers | Mar 19, 2006 | 7.5 | 31 | NO | YES |
CVE-2008-5968HIGH Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cook | Jan 26, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-5967HIGH admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar | Jan 26, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-5840HIGH PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1. | Jan 5, 2009 | 7.5 | 29 | NO | YES |
CVE-2006-1292MEDIUM Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traver | Mar 19, 2006 | 5.0 | 23 | NO | YES |
CVE-2006-6824MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via t | Dec 29, 2006 | 4.3 | 21 | NO | YES |
CVE-2005-3366MEDIUM PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the p | Oct 30, 2005 | 6.8 | 18 | NO | NO |
CVE-2011-3780MEDIUM PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstra | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2006-0648MEDIUM Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameter | Feb 13, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-3319MEDIUM Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter. | Jun 30, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Icalendar.
Media articles that mention a CVE ID that affects a product developed by Php Icalendar — matched by CVE ID, not by vendor name.