Php Icalendar

Vendor:

First CVE: Oct 30, 2005 · Active for 20 years

10
Total CVEs
Bottom 1%
2.5
Avg CVEs / Year
Bottom 1%
6.0
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Php Icalendar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 30, 2005
20 years ago
Most Recent CVE
Sep 24, 2011
5,417 days ago

CVE Severity & Scoring

Php Icalendar10 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown10 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown10 (100.0%)
User Interaction
None0 (0.0%)
Unknown10 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown10 (100.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers
Mar 19, 20067.531NOYES
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cook
Jan 26, 20097.529NOYES
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar
Jan 26, 20097.529NOYES
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.
Jan 5, 20097.529NOYES
Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traver
Mar 19, 20065.023NOYES
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via t
Dec 29, 20064.321NOYES
PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the p
Oct 30, 20056.818NONO
PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstra
Sep 24, 20115.017NONO
Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameter
Feb 13, 20065.015NONO
Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter.
Jun 30, 20064.314NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
60.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Php Icalendar

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.415.01.2%00
2.2_beta14.32.4%01
2.2425.92.9%02
2.2337.53.1%03
2.2246.72.9%04
2.2137.53.1%03
2.237.53.1%03
2.166.73.5%05
2.0c67.03.6%05
2.0b36.44.0%02
2.0a236.44.0%02
2.0.176.73.4%05
2.066.73.5%05
1.146.72.9%04
1.037.53.1%03
0.9.537.53.1%03
0.937.53.1%03
0.837.53.1%03
0.737.53.1%03