VendorsRob Suttonphp-nuke_event_calendar2.13
Vulnerabilities

Rob Sutton Php-nuke Event Calendar 2.13

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2004-1530
SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.
Published 2005-02-19 · Modified
7.5EPSS 0.013
CVE-2004-1528
The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.
Published 2005-02-19 · Modified
5.0EPSS 0.015
CVE-2004-1529
Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.
Published 2005-02-19 · Modified
4.3EPSS 0.014