The document describes a SQL injection vulnerability in Calendarix's cal_cat.php file, where the 'limit' parameter is improperly sanitized, allowing remote attackers to inject malicious SQL queries. The vulnerability affects all versions, including a 0-day at the time of disclosure.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:Calendarix (all versions)
No auth needed
Prerequisites:Access to the vulnerable endpoint (cal_cat.php)