Files
CVEs-PoC/2008/CVE-2008-5967.md
T
2025-09-29 21:09:30 +02:00

741 B

CVE-2008-5967

Description

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

POC

Reference

Github

No PoCs found on GitHub currently.