CVE-2000-1072

iCal 2.1 - Code Injection

Title source: llm

Description

iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.

Exploits (1)

exploitdb WORKING POC VERIFIED
by @stake · bashlocalsolaris
https://www.exploit-db.com/exploits/20275

Scores

EPSS 0.0040
EPSS Percentile 61.0%

Details

Status published
Products (1)
netscape/iplanet_ical 2.1 patch2
Published Dec 11, 2000
Tracked Since Feb 18, 2026