vendor:
php iCalendar
by:
rgod
9.8
CVSS
CRITICAL
Remote Command Execution
78
CWE
Product Name: php iCalendar
Affected Version From: 2
Affected Version To: 2.21
Patch Exists: NO
Related CWE: CVE-2006-1234
CPE: a:phpicalendar:phpicalendar:2.21
Platforms Tested:
php iCalendar <=2.21 publish.ical.php remote cmmnds xctn
This exploit allows an attacker to execute remote commands on the target server.
Mitigation:
Disable the "phpicalendar_publishing" feature in the config.inc.php file.