Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| simple_php_agenda | simple_php_agenda | 2.0.0 |
| simple_php_agenda | simple_php_agenda | 2.1.0 |
| simple_php_agenda | simple_php_agenda | 2.2.0 |
| simple_php_agenda | simple_php_agenda | 2.2.3 |
| simple_php_agenda | simple_php_agenda | 2.2.2 |
| simple_php_agenda | simple_php_agenda | * |
| simple_php_agenda | simple_php_agenda | 2.2.1 |
SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| simple_php_agenda | simple_php_agenda | 2.2.8 |