CVE-2012-2925
Published May 21, 2012SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action.
Vendor/product archive
2 CVEs tagged to simple_php_agenda / simple_php_agenda — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action.
Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in th…