Show filters
116 Total Results
Displaying 111-116 of 116
Sort by:
Attacker Value
Unknown

CVE-2017-2150

Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.
0
Attacker Value
Unknown

CVE-2015-7320

Disclosure Date: September 29, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-7319

Disclosure Date: September 29, 2015 (last updated October 05, 2023)
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.
0
Attacker Value
Unknown

CVE-2014-10015

Disclosure Date: January 13, 2015 (last updated October 05, 2023)
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown

CVE-2014-10014

Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an update action to the AdminOptions controller or conduct cross-site scripting (XSS) attacks via the (2) event_title parameter in a create action to the AdminEvents controller or (3) category_title parameter in a create action to the AdminCategories controller.
0
Attacker Value
Unknown

CVE-2011-5045

Disclosure Date: December 30, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTML via the page_info_message parameter.
0