PT-2006-3995 · Calendarix · Calendar Mx Basic
Federico Fazzi
·
Published
2006-06-19
·
Updated
2017-07-20
·
CVE-2006-3094
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Calendarix Basic versions 0.7.20060401 and earlier
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
id parameter in API endpoints such as "cal event.php" and "cal popup.php", particularly when magic quotes gpc is disabled.Recommendations
For Calendarix Basic versions 0.7.20060401 and earlier, consider disabling the
id parameter in the affected API endpoints "cal event.php" and "cal popup.php" until a patch is available. Additionally, enabling magic quotes gpc can help mitigate the risk of SQL injection attacks.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Calendar Mx Basic