6.5
CVSSv2

CVE-2013-3961

Published: 11/03/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in edit_event.php in Simple PHP Agenda prior to 2.2.9 allows remote authenticated users to execute arbitrary SQL commands via the eventid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

abeel simple php agenda

abeel simple php agenda 2.2.1

abeel simple php agenda 2.2.0

abeel simple php agenda 2.1.0

abeel simple php agenda 0.3.0

abeel simple php agenda 0.2.7

abeel simple php agenda 0.2.0

abeel simple php agenda 0.1.2

abeel simple php agenda 2.2.5

abeel simple php agenda 2.2.4

abeel simple php agenda 1.0.0

abeel simple php agenda 0.3.3

abeel simple php agenda 0.2.4

abeel simple php agenda 0.2.3

abeel simple php agenda 2.2.7

abeel simple php agenda 2.2.6

abeel simple php agenda 2.0.0

abeel simple php agenda 1.0.1

abeel simple php agenda 0.2.6

abeel simple php agenda 0.2.5

abeel simple php agenda 0.1.1

abeel simple php agenda 0.1

abeel simple php agenda 2.2.3

abeel simple php agenda 2.2.2

abeel simple php agenda 0.3.2

abeel simple php agenda 0.3.1

abeel simple php agenda 0.2.2

abeel simple php agenda 0.2.1

Exploits

============================================= WEBERA ALERT ADVISORY 02 - Discovered by: Anthony Dubuissez - Severity: high - CVE Request – 05/06/2013 - CVE Assign – 06/06/2013 - CVE Number – CVE-2013-3961 - Vendor notification – 06/06/2013 - Vendor reply – 10/06/2013 - Public disclosure – 11/06/2013 ===================================== ...
Simple PHP Agenda version 228 suffers from a remote SQL injection vulnerability ...