CVE-2006-1372

1WebCalendar <4.0 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.

Exploits (3)

exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappscfm
https://www.exploit-db.com/exploits/27455
exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappscfm
https://www.exploit-db.com/exploits/27457
exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappscfm
https://www.exploit-db.com/exploits/27456

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25373
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24023
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17193
Exploit third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19329
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1040
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24021
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24022

Scores

EPSS 0.0087
EPSS Percentile 75.4%

Details

Status published
Products (1)
benson_it_solutions/1webcalendar < 4.0
Published Mar 24, 2006
Tracked Since Feb 18, 2026