PT-2006-3995 · Calendarix · Calendar Mx Basic

Federico Fazzi

·

Published

2006-06-19

·

Updated

2017-07-20

·

CVE-2006-3094

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Calendarix Basic versions 0.7.20060401 and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the id parameter in API endpoints such as "cal event.php" and "cal popup.php", particularly when magic quotes gpc is disabled.
Recommendations For Calendarix Basic versions 0.7.20060401 and earlier, consider disabling the id parameter in the affected API endpoints "cal event.php" and "cal popup.php" until a patch is available. Additionally, enabling magic quotes gpc can help mitigate the risk of SQL injection attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3094

Affected Products

Calendar Mx Basic