CVE-2006-6824

N/A Unknown
Published: December 29, 2006 Modified: April 23, 2026
View on NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php, (f) rss/index.php, (g) print.php, and (h) preferences.php; the (2) cpath parameter in (i) day.php, (j) month.php, (k) year.php, (l) week.php, and (m) search.php; the (3) query parameter in search.php; and possibly the cpath, (4) unset, and (5) set parameters in a setcookie action in preferences.php; different vectors than CVE-2006-3319. NOTE: it was later reported that vectors b, c, and d also affect 2.24.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/23499
Source: cve@mitre.org
Vendor Advisory
http://securitytracker.com/id?1017449
Source: cve@mitre.org
Exploit
http://www.osvdb.org/32493
Source: cve@mitre.org
http://www.osvdb.org/32494
Source: cve@mitre.org
http://www.osvdb.org/32495
Source: cve@mitre.org
http://www.osvdb.org/32496
Source: cve@mitre.org
http://www.osvdb.org/32497
Source: cve@mitre.org
http://www.osvdb.org/32498
Source: cve@mitre.org
http://www.osvdb.org/32499
Source: cve@mitre.org
http://www.osvdb.org/32500
Source: cve@mitre.org
http://www.securityfocus.com/bid/21792
Source: cve@mitre.org
Exploit
http://secunia.com/advisories/23499
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://securitytracker.com/id?1017449
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.osvdb.org/32493
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/32494
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/32495
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/32496
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/32497
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/32498
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/32499
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/32500
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/485397/100/200/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/21792
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/31146
Source: af854a3a-2127-422b-91ae-364da2661108

28 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.9%
83th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

php_icalendar