VYPR

phpScheduleIt

by Phpscheduleit

CVEs (5)

  • CVE-2008-6132Feb 13, 2009
    risk 0.05cvss epss 0.26

    Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via the start_date parameter.

  • CVE-2009-0820Mar 5, 2009
    risk 0.03cvss epss 0.05

    Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php. NOTE: the start_date/reserve.php vector is already…

  • CVE-2011-3787Sep 24, 2011
    risk 0.00cvss epss 0.01

    phpScheduleIt 1.2.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/schedule.template.php and certain other files.

  • CVE-2008-3268Jul 24, 2008
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names. NOTE: some of these…

  • CVE-2004-2469Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.