sweetphp kayıtları
sweetphp üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2007-3515Kavram kanıtı | SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands vsweetphp · totalcalendar | Kritik10,0 | — | %1,8 | 3 Tem 2007 |
31İzleyin | CVE-2009-4929Kavram kanıtı | admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrarsweetphp · totalcalender · CWE-287 | Yüksek7,5 | — | %2,5 | 12 Tem 2010 |
31İzleyin | CVE-2009-4974Kavram kanıtı | Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have sweetphp · totalcalendar · CWE-22 | Yüksek7,5 | — | %2,3 | 28 Tem 2010 |
30İzleyin | CVE-2009-4928İstismar yok | PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL isweetphp · totalcalendar · CWE-94 | Yüksek7,5 | — | %1,3 | 12 Tem 2010 |
30İzleyin | CVE-2009-4973Kavram kanıtı | SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal pasweetphp · totalcalendar · CWE-89 | Yüksek7,5 | — | %0,9 | 28 Tem 2010 |
29İzleyin | CVE-2006-7055Kavram kanıtı | PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code viasweetphp · totalcalendar | Orta6,8 | — | %5,6 | 23 Şub 2007 |
28İzleyin | CVE-2009-1406Kavram kanıtı | Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local filesweetphp · totalcalendar · CWE-22 | Orta6,8 | — | %1,9 | 24 Nis 2009 |
26İzleyin | CVE-2006-1922Kavram kanıtı | PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP csweetphp · totalcalendar | Orta6,4 | — | %3,0 | 20 Nis 2006 |
- CVE-2007-351541Planlayın
SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands v
KritikCVSS 10,0Kavram kanıtıEPSS %2sweetphp · totalcalendar3 Tem 2007
- CVE-2009-492931İzleyin
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrar
YüksekCVSS 7,5Kavram kanıtıEPSS %2sweetphp · totalcalender12 Tem 2010
- CVE-2009-497431İzleyin
Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have
YüksekCVSS 7,5Kavram kanıtıEPSS %2sweetphp · totalcalendar28 Tem 2010
- CVE-2009-492830İzleyin
PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL i
YüksekCVSS 7,5İstismar yokEPSS %1sweetphp · totalcalendar12 Tem 2010
- CVE-2009-497330İzleyin
SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal pa
YüksekCVSS 7,5Kavram kanıtıEPSS %1sweetphp · totalcalendar28 Tem 2010
- CVE-2006-705529İzleyin
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via
OrtaCVSS 6,8Kavram kanıtıEPSS %6sweetphp · totalcalendar23 Şub 2007
- CVE-2009-140628İzleyin
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local file
OrtaCVSS 6,8Kavram kanıtıEPSS %2sweetphp · totalcalendar24 Nis 2009
- CVE-2006-192226İzleyin
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP c
OrtaCVSS 6,4Kavram kanıtıEPSS %3sweetphp · totalcalendar20 Nis 2006