← Back

Sweetphp

sweetphp

8 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Totalcalendar
totalcalendar
Totalcalender
totalcalender

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sweetphp
1Totalcalendar
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the box parameter.
1Sweetphp
1Totalcalendar
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.
1Sweetphp
1Totalcalender
Apr 29, 2026
Jul 12, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.
1Sweetphp
1Totalcalendar
Apr 29, 2026
Jul 12, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922 and CVE-2006-7055...Show more
PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922 and CVE-2006-7055.Show less
1Sweetphp
1Totalcalendar
Apr 23, 2026
Apr 24, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the include parameter.
1Sweetphp
1Totalcalendar
Apr 23, 2026
Jul 3, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Sweetphp
1Totalcalendar
Apr 23, 2026
Feb 24, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
1Sweetphp
1Totalcalendar
Apr 16, 2026
Apr 20, 2006
N/A· v4
N/A· v3
6.4 MEDIUM· v2
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.