Back
CVE-2005-3366
PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher.
Published: Oct 30, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| php_icalendar | php_icalendar | 2.0.1 |
| php_icalendar | php_icalendar | 2.0a2 |
| php_icalendar | php_icalendar | 2.0b |
| php_icalendar | php_icalendar | 2.0c |
GitHub Security Advisory GHSA-g8c8-8m7v-7v94
PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote...
References (18)
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0512.html Exploit, Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=113025930517426&w=2
- http://secunia.com/advisories/17328/ Vendor Advisory
- http://securityreason.com/securityalert/113
- http://securitytracker.com/id?1015102
- http://www.securityfocus.com/bid/15193
- http://www.ush.it/2005/10/25/php-icalendar-css/ Exploit, Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2204
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22864
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0512.html Exploit, Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=113025930517426&w=2
- http://secunia.com/advisories/17328/ Vendor Advisory
- http://securityreason.com/securityalert/113
- http://securitytracker.com/id?1015102
- http://www.securityfocus.com/bid/15193
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
2.37%
Top 17% most likely to be exploited
Threat Score
27.9 / 100
Data Sources
NVD
EPSS
GitHub