MidnightBSD

Advisories for eventum_project

CVE-2014-1631 MEDIUM

Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-275,

Products Affected

Vendor Product Version
eventum_project eventum *
CVE-2014-1632 HIGH

htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-275,

Products Affected

Vendor Product Version
eventum_project eventum *
CVE-2018-16761 MEDIUM

Eventum before 3.4.0 has an open redirect vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
eventum_project eventum *