PT-2006-3995 · Calendarix · Calendar Mx Basic

Federico Fazzi

·

Publicado

2006-06-19

·

Atualizado

2017-07-20

·

CVE-2006-3094

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Calendarix Basic versions 0.7.20060401 and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the id parameter in API endpoints such as "cal event.php" and "cal popup.php", particularly when magic quotes gpc is disabled.
Recommendations For Calendarix Basic versions 0.7.20060401 and earlier, consider disabling the id parameter in the affected API endpoints "cal event.php" and "cal popup.php" until a patch is available. Additionally, enabling magic quotes gpc can help mitigate the risk of SQL injection attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3094

Produtos afetados

Calendar Mx Basic