VYPR

Simple PHP Agenda

by Simple PHP Agenda

CVEs (4)

  • CVE-2012-1978May 21, 2015
    risk 0.03cvss epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Agenda 2.2.8 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via a request to auth/process.php, (2) delete an administrator via a…

  • CVE-2013-3961Mar 11, 2014
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to execute arbitrary SQL commands via the eventid parameter.

  • CVE-2012-2925May 21, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action.

  • CVE-2008-3031Jul 7, 2008
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.