Записи sweetphp
8 опубликованных записей вендора sweetphp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2007-3515Proof of concept | SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands vsweetphp · totalcalendar | Критическая10,0 | — | 1,8 % | 3 июл. 2007 г. |
31Наблюдать | CVE-2009-4929Proof of concept | admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrarsweetphp · totalcalender · CWE-287 | Высокая7,5 | — | 2,5 % | 12 июл. 2010 г. |
31Наблюдать | CVE-2009-4974Proof of concept | Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have sweetphp · totalcalendar · CWE-22 | Высокая7,5 | — | 2,3 % | 28 июл. 2010 г. |
30Наблюдать | CVE-2009-4928Эксплойта нет | PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL isweetphp · totalcalendar · CWE-94 | Высокая7,5 | — | 1,3 % | 12 июл. 2010 г. |
30Наблюдать | CVE-2009-4973Proof of concept | SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal pasweetphp · totalcalendar · CWE-89 | Высокая7,5 | — | 0,9 % | 28 июл. 2010 г. |
29Наблюдать | CVE-2006-7055Proof of concept | PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code viasweetphp · totalcalendar | Средняя6,8 | — | 5,6 % | 23 февр. 2007 г. |
28Наблюдать | CVE-2009-1406Proof of concept | Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local filesweetphp · totalcalendar · CWE-22 | Средняя6,8 | — | 1,9 % | 24 апр. 2009 г. |
26Наблюдать | CVE-2006-1922Proof of concept | PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP csweetphp · totalcalendar | Средняя6,4 | — | 3,0 % | 20 апр. 2006 г. |
- CVE-2007-351541В плане
SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands v
КритическаяCVSS 10,0Proof of conceptEPSS 2 %sweetphp · totalcalendar3 июл. 2007 г.
- CVE-2009-492931Наблюдать
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrar
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %sweetphp · totalcalender12 июл. 2010 г.
- CVE-2009-497431Наблюдать
Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %sweetphp · totalcalendar28 июл. 2010 г.
- CVE-2009-492830Наблюдать
PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL i
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sweetphp · totalcalendar12 июл. 2010 г.
- CVE-2009-497330Наблюдать
SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal pa
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %sweetphp · totalcalendar28 июл. 2010 г.
- CVE-2006-705529Наблюдать
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via
СредняяCVSS 6,8Proof of conceptEPSS 6 %sweetphp · totalcalendar23 февр. 2007 г.
- CVE-2009-140628Наблюдать
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local file
СредняяCVSS 6,8Proof of conceptEPSS 2 %sweetphp · totalcalendar24 апр. 2009 г.
- CVE-2006-192226Наблюдать
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP c
СредняяCVSS 6,4Proof of conceptEPSS 3 %sweetphp · totalcalendar20 апр. 2006 г.