CVE-2008-5967

Publication date 26 January 2009

Last updated 24 July 2024


Ubuntu priority

Description

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

Status

Package Ubuntu Release Status
phpicalendar 10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty Ignored end of life
8.10 intrepid Ignored end of life, was needed
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release