CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2009-4974 HIGH

Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other i…

CVSS 7.5 EPSS 2.32% Jul 27, 2010
CVE-2009-4973 HIGH

SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a Switch…

CVSS 7.5 EPSS 0.95% Jul 27, 2010
CVE-2009-4929 HIGH

admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the…

CVSS 7.5 EPSS 2.46% Jul 9, 2010
CVE-2009-4928 HIGH

PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir param…

CVSS 7.5 EPSS 1.32% Jul 9, 2010
CVE-2009-1406 MEDIUM

Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot…

CVSS 6.8 EPSS 1.90% Apr 24, 2009
CVE-2007-3515 HIGH

SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 10.0 EPSS 1.82% Jul 3, 2007
CVE-2006-7055 MEDIUM

PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_d…

CVSS 6.8 EPSS 5.60% Feb 24, 2007
CVE-2006-1922 MEDIUM

PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in th…

CVSS 6.4 EPSS 3.00% Apr 20, 2006

Showing 1 to 8 CVEs · page 1