accept no compromises
Showing 1 - 1 of 1 RSS Feed

Files

secunia-calendarix.txt
Posted Aug 26, 2008
Site secunia.com

Secunia Research has discovered two vulnerabilities in Calendarix Basic, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "catsearch" parameter in cal_search.php and "catview" in cal_cat.php is not properly sanitized before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Calendarix Basic 0.8.20071118 is affected.

tags | advisory, arbitrary, php, vulnerability, sql injection
advisories | CVE-2008-2429
MD5 | 25805f56ddb5ea080e60cc240a6e595d
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close