Skip to content
Noroxi

sweetphp records

8 published records for vendor sweetphp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
6
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

8 records
  • SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands v

    CriticalCVSS 10.0Proof of conceptEPSS 2%

    sweetphp · totalcalendarJul 3, 2007

  • CVE-2009-4929
    31Monitor

    admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrar

    HighCVSS 7.5Proof of conceptEPSS 2%

    sweetphp · totalcalenderJul 12, 2010

  • CVE-2009-4974
    31Monitor

    Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have

    HighCVSS 7.5Proof of conceptEPSS 2%

    sweetphp · totalcalendarJul 28, 2010

  • CVE-2009-4928
    30Monitor

    PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL i

    HighCVSS 7.5No exploitEPSS 1%

    sweetphp · totalcalendarJul 12, 2010

  • CVE-2009-4973
    30Monitor

    SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal pa

    HighCVSS 7.5Proof of conceptEPSS 1%

    sweetphp · totalcalendarJul 28, 2010

  • CVE-2006-7055
    29Monitor

    PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via

    MediumCVSS 6.8Proof of conceptEPSS 6%

    sweetphp · totalcalendarFeb 23, 2007

  • CVE-2009-1406
    28Monitor

    Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local file

    MediumCVSS 6.8Proof of conceptEPSS 2%

    sweetphp · totalcalendarApr 24, 2009

  • CVE-2006-1922
    26Monitor

    PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP c

    MediumCVSS 6.4Proof of conceptEPSS 3%

    sweetphp · totalcalendarApr 20, 2006