CVE-2008-1344
MyioSoft EasyCalendar <4.0tr - SQL Injection
Title source: llmDescription
Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in a dayview action to plugins/calendar/calendar_backend.php and the (2) page parameter to ajaxp_backend.php.
Exploits (1)
References (5)
Scores
EPSS
0.0045
EPSS Percentile
63.3%
Classification
CWE
CWE-89
Status
draft
Affected Products (1)
myiosoft/easycalendar
Timeline
Published
Mar 17, 2008
Tracked Since
Feb 18, 2026