Записи phpicalendar
4 опубликованных записей вендора phpicalendar.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2008-5967Proof of concept | admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allophpicalendar · phpicalendar · CWE-287 | Высокая7,5 | — | 3,3 % | 26 янв. 2009 г. |
31Наблюдать | CVE-2008-5840Proof of concept | PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies tphpicalendar · phpicalendar · CWE-264 | Высокая7,5 | — | 3,0 % | 5 янв. 2009 г. |
31Наблюдать | CVE-2008-5968Proof of concept | Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary lophpicalendar · phpicalendar · CWE-22 | Высокая7,5 | — | 2,9 % | 26 янв. 2009 г. |
20Наблюдать | CVE-2011-3780Эксплойта нет | PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatiophpicalendar · php icalendar · CWE-200 | Средняя5,0 | — | 1,2 % | 23 сент. 2011 г. |
- CVE-2008-596731Наблюдать
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allo
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phpicalendar · phpicalendar26 янв. 2009 г.
- CVE-2008-584031Наблюдать
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies t
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phpicalendar · phpicalendar5 янв. 2009 г.
- CVE-2008-596831Наблюдать
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary lo
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phpicalendar · phpicalendar26 янв. 2009 г.
- CVE-2011-378020Наблюдать
PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio
СредняяCVSS 5,0Эксплойта нетEPSS 1 %phpicalendar · php icalendar23 сент. 2011 г.