MidnightBSD

Advisories for simple_php_agenda

CVE-2008-3031 HIGH

Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
simple_php_agenda simple_php_agenda 2.0.0
simple_php_agenda simple_php_agenda 2.1.0
simple_php_agenda simple_php_agenda 2.2.0
simple_php_agenda simple_php_agenda 2.2.3
simple_php_agenda simple_php_agenda 2.2.2
simple_php_agenda simple_php_agenda *
simple_php_agenda simple_php_agenda 2.2.1
CVE-2012-2925 HIGH

SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
simple_php_agenda simple_php_agenda 2.2.8