CVE-2008-5840

PHP iCalendar <2.24 - Auth Bypass

Title source: llm

Description

PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stack · textwebappsphp
https://www.exploit-db.com/exploits/6526

Scores

EPSS 0.0226
EPSS Percentile 84.4%

Classification

CWE
CWE-264
Status draft

Affected Products (17)

phpicalendar/phpicalendar < 2.24
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
phpicalendar/phpicalendar
... and 2 more

Timeline

Published Jan 05, 2009
Tracked Since Feb 18, 2026