Unrated severityNVD Advisory· Published Jan 26, 2009· Updated Jun 16, 2026
CVE-2008-5967
CVE-2008-5967
Description
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18cpe:2.3:a:phpicalendar:phpicalendar:*:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:phpicalendar:phpicalendar:*:*:*:*:*:*:*:*range: <=2.3.4
- cpe:2.3:a:phpicalendar:phpicalendar:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:0.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.0:beta:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.0c:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.21:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.22:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.23:*:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.23:rc1:*:*:*:*:*:*
- cpe:2.3:a:phpicalendar:phpicalendar:2.24:*:*:*:*:*:*:*
- (no CPE)range: <=2.3.4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.