Php Icalendar
Vendor:
First CVE: Oct 30, 2005 · Active for 20 years
10
Total CVEs
Bottom 1%
2.5
Avg CVEs / Year
Bottom 1%
6.0
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Php Icalendar over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 30, 2005
20 years ago
Most Recent CVE
Sep 24, 2011
5,417 days ago
CVE Severity & Scoring
Php Icalendar10 CVEs
60%
40%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown10 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown10 (100.0%)
User Interaction
None0 (0.0%)
Unknown10 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown10 (100.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1291HIGH publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers | Mar 19, 2006 | 7.5 | 31 | NO | YES |
CVE-2008-5968HIGH Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cook | Jan 26, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-5967HIGH admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar | Jan 26, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-5840HIGH PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1. | Jan 5, 2009 | 7.5 | 29 | NO | YES |
CVE-2006-1292MEDIUM Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traver | Mar 19, 2006 | 5.0 | 23 | NO | YES |
CVE-2006-6824MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via t | Dec 29, 2006 | 4.3 | 21 | NO | YES |
CVE-2005-3366MEDIUM PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the p | Oct 30, 2005 | 6.8 | 18 | NO | NO |
CVE-2011-3780MEDIUM PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstra | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2006-0648MEDIUM Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameter | Feb 13, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-3319MEDIUM Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter. | Jun 30, 2006 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
60.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Php Icalendar
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.4 | 1 | 5.0 | 1.2% | 0 | 0 |
| 2.2_beta | 1 | 4.3 | 2.4% | 0 | 1 |
| 2.24 | 2 | 5.9 | 2.9% | 0 | 2 |
| 2.23 | 3 | 7.5 | 3.1% | 0 | 3 |
| 2.22 | 4 | 6.7 | 2.9% | 0 | 4 |
| 2.21 | 3 | 7.5 | 3.1% | 0 | 3 |
| 2.2 | 3 | 7.5 | 3.1% | 0 | 3 |
| 2.1 | 6 | 6.7 | 3.5% | 0 | 5 |
| 2.0c | 6 | 7.0 | 3.6% | 0 | 5 |
| 2.0b | 3 | 6.4 | 4.0% | 0 | 2 |
| 2.0a2 | 3 | 6.4 | 4.0% | 0 | 2 |
| 2.0.1 | 7 | 6.7 | 3.4% | 0 | 5 |
| 2.0 | 6 | 6.7 | 3.5% | 0 | 5 |
| 1.1 | 4 | 6.7 | 2.9% | 0 | 4 |
| 1.0 | 3 | 7.5 | 3.1% | 0 | 3 |
| 0.9.5 | 3 | 7.5 | 3.1% | 0 | 3 |
| 0.9 | 3 | 7.5 | 3.1% | 0 | 3 |
| 0.8 | 3 | 7.5 | 3.1% | 0 | 3 |
| 0.7 | 3 | 7.5 | 3.1% | 0 | 3 |