Webcal · Webcal · CVE-2009-1945
Name of the Vulnerable Software and Affected Versions:
WebCal version 3.04
Description:
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the `event id` parameter in the "webCal3 detail.asp" page.
Recommendations:
For WebCal version 3.04, consider restricting access to the `event id` parameter in the "webCal3 detail.asp" page until a patch is available. As a temporary workaround, avoid using the `event id` parameter in the affected page to minimize the risk of exploitation.