Lucene search

K

Eventum Security Vulnerabilities

cve
cve

CVE-2018-11569

Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version...

9.8CVSS

9.4AI Score

0.002EPSS

2019-09-05 04:15 PM
28
cve
cve

CVE-2018-12623

An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page...

6.1CVSS

5.9AI Score

0.001EPSS

2019-07-10 12:15 PM
17
cve
cve

CVE-2018-12627

An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authorized_issues...

6.1CVSS

5.9AI Score

0.001EPSS

2019-07-10 12:15 PM
19
cve
cve

CVE-2018-12622

An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name...

6.1CVSS

5.9AI Score

0.001EPSS

2019-07-10 12:15 PM
19
cve
cve

CVE-2018-12625

An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values...

6.1CVSS

5.9AI Score

0.001EPSS

2019-07-10 12:15 PM
17
cve
cve

CVE-2018-12626

An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat...

6.1CVSS

5.9AI Score

0.001EPSS

2019-07-10 12:15 PM
16
cve
cve

CVE-2018-12628

An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin...

8.8CVSS

8.6AI Score

0.001EPSS

2019-07-10 12:15 PM
17
cve
cve

CVE-2018-12621

An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page...

6.1CVSS

6.2AI Score

0.001EPSS

2019-07-05 05:15 PM
278
cve
cve

CVE-2018-12624

An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix...

6.1CVSS

5.9AI Score

0.001EPSS

2019-05-24 06:29 PM
28
cve
cve

CVE-2018-16761

Eventum before 3.4.0 has an open redirect...

6.1CVSS

6.2AI Score

0.001EPSS

2018-09-09 09:29 PM
26
cve
cve

CVE-2014-1632

htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname...

8.1CVSS

8.2AI Score

0.006EPSS

2018-01-31 06:29 PM
23
cve
cve

CVE-2014-1631

Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to...

7.5CVSS

7.6AI Score

0.02EPSS

2018-01-31 06:29 PM
27
cve
cve

CVE-2005-2467

Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to...

6AI Score

0.014EPSS

2006-06-06 08:03 PM
22
cve
cve

CVE-2005-2468

Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6).....

8.9AI Score

0.009EPSS

2006-06-06 08:03 PM
28