CVE-2006-1292

PHP iCalendar <2.21 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1292. PoCs published by rgod.

AI-analyzed exploit summary This exploit leverages a local file inclusion vulnerability in php iCalendar <=2.21 by injecting malicious PHP code into Apache log files via HTTP headers and then including the log file through manipulated cookie values. The exploit uses null byte injection to bypass path restrictions and achieve remote command execution.

Description

Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1585

This exploit leverages a local file inclusion vulnerability in php iCalendar <=2.21 by injecting malicious PHP code into Apache log files via HTTP headers and then including the log file through manipulated cookie values. The exploit uses null byte injection to bypass path restrictions and achieve remote command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: php iCalendar <=2.21
No auth needed
Prerequisites: Target must have php iCalendar <=2.21 installed · Apache log files must be writable and accessible via the vulnerability · PHP must be configured to allow file inclusion via cookies
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17125
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19285
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1019
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1585

Scores

EPSS 0.0278
EPSS Percentile 84.5%

Details

Status published
Products (7)
php_icalendar/php_icalendar 2.0
php_icalendar/php_icalendar 2.0.1
php_icalendar/php_icalendar 2.0a2
php_icalendar/php_icalendar 2.0b
php_icalendar/php_icalendar 2.0c
php_icalendar/php_icalendar 2.1
php_icalendar/php_icalendar < 2.2.1
Published Mar 19, 2006
Tracked Since Feb 18, 2026