Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c74-rc32-qc6j

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

EPSS

Процентиль: 88%
0.03779
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
около 17 лет назад

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

nvd
около 17 лет назад

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

debian
около 17 лет назад

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not req ...

EPSS

Процентиль: 88%
0.03779
Низкий

Дефекты

CWE-287