CVE-2006-1372

Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.
Configurations

Configuration 1 (hide)

cpe:2.3:a:benson_it_solutions:1webcalendar:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-03-24 02:02

Updated : 2024-02-04 16:52


NVD link : CVE-2006-1372

Mitre link : CVE-2006-1372

CVE.ORG link : CVE-2006-1372


JSON object : View

Products Affected

benson_it_solutions

  • 1webcalendar