php-calendar records
6 published records for vendor php-calendar.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2004-1423Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtphp-calendar · php-calendar · CWE-94 | High7.5 | — | 15.5% | Dec 31, 2004 |
31Monitor | CVE-2009-3702Proof of concept | Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files viaphp-calendar · php-calendar · CWE-22 | High7.5 | — | 2.4% | Dec 22, 2009 |
31Monitor | CVE-2005-1397No exploit | SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknophp-calendar · php-calendar | High7.5 | — | 1.8% | May 3, 2005 |
24Monitor | CVE-2017-6485No exploit | A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03.php-calendar · php-calendar · CWE-79 | Medium6.1 | — | 0.7% | Mar 5, 2017 |
20Monitor | CVE-2022-4455No exploit | sproctor php-calendar index.php cross site scriptingphp-calendar · php-calendar · CWE-79 | Medium5.1 | — | 0.6% | Dec 13, 2022 |
17Monitor | CVE-2010-2041No exploit | Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitraryphp-calendar · php-calendar · CWE-79 | Medium4.3 | — | 1.3% | May 25, 2010 |
- CVE-2004-142335Monitor
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virt
HighCVSS 7.5Proof of conceptEPSS 15%php-calendar · php-calendarDec 31, 2004
- CVE-2009-370231Monitor
Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via
HighCVSS 7.5Proof of conceptEPSS 2%php-calendar · php-calendarDec 22, 2009
- CVE-2005-139731Monitor
SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unkno
HighCVSS 7.5No exploitEPSS 2%php-calendar · php-calendarMay 3, 2005
- CVE-2017-648524Monitor
A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03.
MediumCVSS 6.1No exploitEPSS 1%php-calendar · php-calendarMar 5, 2017
- CVE-2022-445520Monitor
sproctor php-calendar index.php cross site scripting
MediumCVSS 5.1No exploitEPSS 1%php-calendar · php-calendarDec 13, 2022
- CVE-2010-204117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary
MediumCVSS 4.3No exploitEPSS 1%php-calendar · php-calendarMay 25, 2010