CVE-2008-5797

advCalendar Extension < 0.3.1 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the advCalendar extension 0.3.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46469
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32230

Scores

EPSS 0.0041
EPSS Percentile 61.7%

Details

CWE
CWE-89
Status published
Products (1)
typo3/advcalendar_extension < 0.3.1
Published Dec 31, 2008
Tracked Since Feb 18, 2026