PT-2009-2078 · Develop It Easy · Developiteasy Events Calendar

Cyb3R-1St

·

Published

2009-04-06

·

Updated

2017-09-29

·

CVE-2008-6608

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DevelopItEasy Events Calendar version 1.2
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the "user name" parameter to "admin/index.php", the "user pass" parameter to "admin/index.php", or the id parameter to "calendar details.php".
Recommendations For DevelopItEasy Events Calendar version 1.2, consider restricting access to the vulnerable parameters user name and user pass in the "admin/index.php" endpoint, as well as the id parameter in the "calendar details.php" endpoint, until a fix is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6608

Affected Products

Developiteasy Events Calendar