Vulnerabilities
Vulnerable Software
Sweetphp:  >> Totalcalender  Security Vulnerabilities
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.
CVSS Score
7.5
EPSS Score
0.025
Published
2010-07-12


Contact Us

Shodan ® - All rights reserved