Vulnerabilities > Sweetphp > Totalcalendar > 2.4

DATE CVE VULNERABILITY TITLE RISK
2010-07-28 CVE-2009-4974 Path Traversal vulnerability in Sweetphp Totalcalendar 2.4
Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..
network
low complexity
sweetphp CWE-22
7.5
2010-07-28 CVE-2009-4973 SQL Injection vulnerability in Sweetphp Totalcalendar 2.4
SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.
network
low complexity
sweetphp CWE-89
7.5
2010-07-12 CVE-2009-4928 Code Injection vulnerability in Sweetphp Totalcalendar 2.4
PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922 and CVE-2006-7055.
network
low complexity
sweetphp CWE-94
7.5
2009-04-24 CVE-2009-1406 Path Traversal vulnerability in Sweetphp Totalcalendar 2.4
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a ..
network
sweetphp CWE-22
6.8