Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c74-rc32-qc6j

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

EPSS

Процентиль: 82%
0.018
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 17 лет назад

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

nvd
почти 17 лет назад

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

debian
почти 17 лет назад

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not req ...

EPSS

Процентиль: 82%
0.018
Низкий

Дефекты

CWE-287