Vulnerability Details CVE-2006-1292
Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.062
EPSS Ranking 90.5%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2006-1292
-
cpe:2.3:a:php_icalendar:php_icalendar:*
-
cpe:2.3:a:php_icalendar:php_icalendar:2.0
-
cpe:2.3:a:php_icalendar:php_icalendar:2.0.1
-
cpe:2.3:a:php_icalendar:php_icalendar:2.0a2
-
cpe:2.3:a:php_icalendar:php_icalendar:2.0b
-
cpe:2.3:a:php_icalendar:php_icalendar:2.0c
-
cpe:2.3:a:php_icalendar:php_icalendar:2.1