Total vulnerabilities in the database
Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php. NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132.
Software | From | Fixed in |
---|---|---|
php.brickhost / phpscheduleit | 1.2.0 | 1.2.0.x |
php.brickhost / phpscheduleit | 1.2.3 | 1.2.3.x |
php.brickhost / phpscheduleit | 1.2.4 | 1.2.4.x |
php.brickhost / phpscheduleit | 1.2.2 | 1.2.2.x |
php.brickhost / phpscheduleit | 1.2.0-rc1 | 1.2.0-rc1.x |
php.brickhost / phpscheduleit | 1.2.6 | 1.2.6.x |
php.brickhost / phpscheduleit | 1.0_rc1 | 1.0_rc1.x |
php.brickhost / phpscheduleit | 1.2.5 | 1.2.5.x |
php.brickhost / phpscheduleit | - | 1.2.10.x |
php.brickhost / phpscheduleit | 1.2.7 | 1.2.7.x |
php.brickhost / phpscheduleit | 1.0 | 1.0.x |
php.brickhost / phpscheduleit | 1.2.9 | 1.2.9.x |
php.brickhost / phpscheduleit | 1.2.0-beta | 1.2.0-beta.x |
php.brickhost / phpscheduleit | 1.2.1 | 1.2.1.x |
php.brickhost / phpscheduleit | 1.2.8 | 1.2.8.x |
php.brickhost / phpscheduleit | 1.0.0rc1 | 1.0.0rc1.x |