Php Lite develops a focused set of web-based applications including calendar and meeting-reservation systems, where the durable exposure centers on SQL-injection vulnerabilities arising from improper handling of user input in database queries. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Lite over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3627HIGH Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.ph | Jul 9, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-2973HIGH Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid paramete | Jun 12, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-4009HIGH Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameter | Dec 5, 2005 | 7.5 | 19 | NO | NO |
CVE-2006-1399MEDIUM Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term paramete | Mar 28, 2006 | 4.3 | 14 | NO | NO |
CVE-2006-1401MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) | Mar 28, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Lite.
Media articles that mention a CVE ID that affects a product developed by Php Lite — matched by CVE ID, not by vendor name.