Записи php-calendar
6 опубликованных записей вендора php-calendar.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2004-1423Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtphp-calendar · php-calendar · CWE-94 | Высокая7,5 | — | 15,5 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2009-3702Proof of concept | Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files viaphp-calendar · php-calendar · CWE-22 | Высокая7,5 | — | 2,4 % | 22 дек. 2009 г. |
31Наблюдать | CVE-2005-1397Эксплойта нет | SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknophp-calendar · php-calendar | Высокая7,5 | — | 1,8 % | 3 мая 2005 г. |
24Наблюдать | CVE-2017-6485Эксплойта нет | A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03.php-calendar · php-calendar · CWE-79 | Средняя6,1 | — | 0,7 % | 5 мар. 2017 г. |
20Наблюдать | CVE-2022-4455Эксплойта нет | sproctor php-calendar index.php cross site scriptingphp-calendar · php-calendar · CWE-79 | Средняя5,1 | — | 0,6 % | 13 дек. 2022 г. |
17Наблюдать | CVE-2010-2041Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitraryphp-calendar · php-calendar · CWE-79 | Средняя4,3 | — | 1,3 % | 25 мая 2010 г. |
- CVE-2004-142335Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virt
ВысокаяCVSS 7,5Proof of conceptEPSS 15 %php-calendar · php-calendar31 дек. 2004 г.
- CVE-2009-370231Наблюдать
Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %php-calendar · php-calendar22 дек. 2009 г.
- CVE-2005-139731Наблюдать
SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unkno
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %php-calendar · php-calendar3 мая 2005 г.
- CVE-2017-648524Наблюдать
A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %php-calendar · php-calendar5 мар. 2017 г.
- CVE-2022-445520Наблюдать
sproctor php-calendar index.php cross site scripting
СредняяCVSS 5,1Эксплойта нетEPSS 1 %php-calendar · php-calendar13 дек. 2022 г.
- CVE-2010-204117Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary
СредняяCVSS 4,3Эксплойта нетEPSS 1 %php-calendar · php-calendar25 мая 2010 г.