CVE Tools

Sweetphp

4 CVEs tracked since 2010. Since Jul 2010, none of them reached CISA KEV.

Sweetphp CVEs per month

Jul 2010 to Jul 2010. Point at a month, or focus the strip and use the arrow keys.
Sweetphp CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2010-0740

Products

The products that kept showing up in Sweetphp's monthly top three, with their CVEs summed over those months.

  1. Totalcalendar31 month
  2. Totalcalender11 month

Latest CVEs

The 8 most recently published vulnerabilities affecting Sweetphp.

  1. CVE-2009-4974Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the box pa...7.5
  2. CVE-2009-4973SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.7.5
  3. CVE-2009-4928PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006...7.5
  4. CVE-2009-4929admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.7.5
  5. CVE-2009-1406Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the include parameter.6.8
  6. CVE-2007-3515SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.10.0
  7. CVE-2006-7055PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than ...6.8
  8. CVE-2006-1922PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.6.4

The record

Peak rank
#17 in Jul 2010
Busiest month shown
Jul 2010, 4 CVEs
Months with a KEV entry
0 since Jul 2010
Monthly snapshots
1 since 2010
Sweetphp's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store