Vulnerabilities > ROB Sutton

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-1530 Remote vulnerability in Event Calendar
SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.
network
low complexity
rob-sutton
7.5
2004-12-31 CVE-2004-1529 Remote vulnerability in ROB Sutton PHP-Nuke Event Calendar 2.13
Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.
network
rob-sutton
4.3
2004-12-31 CVE-2004-1528 Remote vulnerability in ROB Sutton PHP-Nuke Event Calendar 2.13
The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.
network
low complexity
rob-sutton
5.0