PT-2006-3995 · Calendarix · Calendar Mx Basic
Federico Fazzi
·
Publicado
2006-06-19
·
Atualizado
2017-07-20
·
CVE-2006-3094
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Calendarix Basic versions 0.7.20060401 and earlier
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
id parameter in API endpoints such as "cal event.php" and "cal popup.php", particularly when magic quotes gpc is disabled.Recommendations
For Calendarix Basic versions 0.7.20060401 and earlier, consider disabling the
id parameter in the affected API endpoints "cal event.php" and "cal popup.php" until a patch is available. Additionally, enabling magic quotes gpc can help mitigate the risk of SQL injection attacks.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Calendar Mx Basic