CVE-2009-0820

Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php.  NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
php.brickhostphpscheduleit
𝑥
≤ 1.2.10
php.brickhostphpscheduleit
1.0
php.brickhostphpscheduleit
1.0.0rc1:rc1
php.brickhostphpscheduleit
1.0_rc1:_rc1
php.brickhostphpscheduleit
1.2.0
php.brickhostphpscheduleit
1.2.0:beta
php.brickhostphpscheduleit
1.2.0:rc1
php.brickhostphpscheduleit
1.2.1
php.brickhostphpscheduleit
1.2.2
php.brickhostphpscheduleit
1.2.3
php.brickhostphpscheduleit
1.2.4
php.brickhostphpscheduleit
1.2.5
php.brickhostphpscheduleit
1.2.6
php.brickhostphpscheduleit
1.2.7
php.brickhostphpscheduleit
1.2.8
php.brickhostphpscheduleit
1.2.9
𝑥
= Vulnerable software versions