Перейти к содержимому
Noroxi

Записи sweetphp

8 опубликованных записей вендора sweetphp.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    8 записей
    • CVE-2007-3515
      41В плане

      SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands v

      КритическаяCVSS 10,0Proof of conceptEPSS 2 %

      sweetphp · totalcalendar3 июл. 2007 г.

    • CVE-2009-4929
      31Наблюдать

      admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrar

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      sweetphp · totalcalender12 июл. 2010 г.

    • CVE-2009-4974
      31Наблюдать

      Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      sweetphp · totalcalendar28 июл. 2010 г.

    • CVE-2009-4928
      30Наблюдать

      PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL i

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      sweetphp · totalcalendar12 июл. 2010 г.

    • CVE-2009-4973
      30Наблюдать

      SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal pa

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      sweetphp · totalcalendar28 июл. 2010 г.

    • CVE-2006-7055
      29Наблюдать

      PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via

      СредняяCVSS 6,8Proof of conceptEPSS 6 %

      sweetphp · totalcalendar23 февр. 2007 г.

    • CVE-2009-1406
      28Наблюдать

      Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local file

      СредняяCVSS 6,8Proof of conceptEPSS 2 %

      sweetphp · totalcalendar24 апр. 2009 г.

    • CVE-2006-1922
      26Наблюдать

      PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP c

      СредняяCVSS 6,4Proof of conceptEPSS 3 %

      sweetphp · totalcalendar20 апр. 2006 г.