Lucene search

K

Php-calendar Security Vulnerabilities

cve
cve

CVE-2022-4455

A vulnerability, which was classified as problematic, was found in sproctor php-calendar. This affects an unknown part of the file index.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch...

6.1CVSS

6AI Score

0.001EPSS

2022-12-13 06:15 PM
28
cve
cve

CVE-2021-42078

PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/events_manager.php title parameter. This can be exploited by an adversary in multiple ways, e.g., to perform actions on the page in the context of other users, or to deface the...

6.1CVSS

6AI Score

0.001EPSS

2021-11-08 05:15 AM
23
cve
cve

CVE-2017-6485

A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed to the "php-calendar-master/error.php" URL. An attacker could execute arbitrary HTML and script code in a browser in.....

6.1CVSS

5.8AI Score

0.001EPSS

2017-03-05 08:59 PM
25
cve
cve

CVE-2010-2041

Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction...

5.9AI Score

0.003EPSS

2010-05-25 02:30 PM
21
cve
cve

CVE-2009-3702

Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via a full pathname in the configfile parameter to (1) update08.php or (2) update10.php. NOTE: in some environments, this can be leveraged for remote file...

7.2AI Score

0.007EPSS

2009-12-22 07:30 PM
22
cve
cve

CVE-2005-1397

SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown...

8.4AI Score

0.008EPSS

2005-05-03 04:00 AM
25
cve
cve

CVE-2004-1423

Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1)...

7.6AI Score

0.184EPSS

2005-02-12 05:00 AM
40