Phpicalendar

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2011-3780

    PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by rss/rss_common.php and certain other files.

    Last Modified: Apr 11, 2025
    Published: Sep 24, 2011

    CVE-2008-5967

    admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

    Last Modified: Apr 23, 2026
    Published: Jan 26, 2009

    CVE-2008-5968

    Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cookie_language parameter in a phpicalendar_* cookie, a different vector than CVE-2006-1292.

    Last Modified: Apr 23, 2026
    Published: Jan 26, 2009

    CVE-2008-5840

    PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.

    Last Modified: Apr 23, 2026
    Published: Jan 05, 2009
    Items Per Page
    Phpicalendar Vulnerabilities & Security CVEs | CVE-DB