Description
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.
Exploits (3)
References (8)
Core 8
Core References
Third Party Advisory x_refsource_misc
http://pridels0.blogspot.com/2006/03/1webcalendar-v-4x-vuln.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25373
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/24023
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/17193
Exploit third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19329
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1040
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/24021
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/24022
Scores
EPSS
0.0087
EPSS Percentile
75.4%
Details
Status
published
Products (1)
benson_it_solutions/1webcalendar
< 4.0
Published
Mar 24, 2006
Tracked Since
Feb 18, 2026