php-calendar kayıtları
php-calendar üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2004-1423Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtphp-calendar · php-calendar · CWE-94 | Yüksek7,5 | — | %15,5 | 31 Ara 2004 |
31İzleyin | CVE-2009-3702Kavram kanıtı | Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files viaphp-calendar · php-calendar · CWE-22 | Yüksek7,5 | — | %2,4 | 22 Ara 2009 |
31İzleyin | CVE-2005-1397İstismar yok | SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknophp-calendar · php-calendar | Yüksek7,5 | — | %1,8 | 3 May 2005 |
24İzleyin | CVE-2017-6485İstismar yok | A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03.php-calendar · php-calendar · CWE-79 | Orta6,1 | — | %0,7 | 5 Mar 2017 |
20İzleyin | CVE-2022-4455İstismar yok | sproctor php-calendar index.php cross site scriptingphp-calendar · php-calendar · CWE-79 | Orta5,1 | — | %0,6 | 13 Ara 2022 |
17İzleyin | CVE-2010-2041İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitraryphp-calendar · php-calendar · CWE-79 | Orta4,3 | — | %1,3 | 25 May 2010 |
- CVE-2004-142335İzleyin
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virt
YüksekCVSS 7,5Kavram kanıtıEPSS %15php-calendar · php-calendar31 Ara 2004
- CVE-2009-370231İzleyin
Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via
YüksekCVSS 7,5Kavram kanıtıEPSS %2php-calendar · php-calendar22 Ara 2009
- CVE-2005-139731İzleyin
SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unkno
YüksekCVSS 7,5İstismar yokEPSS %2php-calendar · php-calendar3 May 2005
- CVE-2017-648524İzleyin
A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03.
OrtaCVSS 6,1İstismar yokEPSS %1php-calendar · php-calendar5 Mar 2017
- CVE-2022-445520İzleyin
sproctor php-calendar index.php cross site scripting
OrtaCVSS 5,1İstismar yokEPSS %1php-calendar · php-calendar13 Ara 2022
- CVE-2010-204117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary
OrtaCVSS 4,3İstismar yokEPSS %1php-calendar · php-calendar25 May 2010