Unrated severityNVD Advisory· Published Jan 5, 2009· Updated Jun 16, 2026
CVE-2008-5840
CVE-2008-5840
Description
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18cpe:2.3:a:phpicalendar:phpicalendar:*:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:phpicalendar:phpicalendar:*:*:*:*:*:*:*:*range: <=2.24
- cpe:2.3:a:phpicalendar:phpicalendar:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:0.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar2.0:alpha_test:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.0:beta:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.0c:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.21:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.22:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.23:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.23:rc1:*:*:*:*:*:*
- (no CPE)range: <=2.24
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.