CVE-2006-1372

Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.
Configurations

Configuration 1 (hide)

cpe:2.3:a:benson_it_solutions:1webcalendar:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:08

Type Values Removed Values Added
References () http://pridels0.blogspot.com/2006/03/1webcalendar-v-4x-vuln.html - () http://pridels0.blogspot.com/2006/03/1webcalendar-v-4x-vuln.html -
References () http://secunia.com/advisories/19329 - Exploit () http://secunia.com/advisories/19329 - Exploit
References () http://www.osvdb.org/24021 - () http://www.osvdb.org/24021 -
References () http://www.osvdb.org/24022 - () http://www.osvdb.org/24022 -
References () http://www.osvdb.org/24023 - () http://www.osvdb.org/24023 -
References () http://www.securityfocus.com/bid/17193 - () http://www.securityfocus.com/bid/17193 -
References () http://www.vupen.com/english/advisories/2006/1040 - () http://www.vupen.com/english/advisories/2006/1040 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/25373 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/25373 -

Information

Published : 2006-03-24 02:02

Updated : 2024-11-21 00:08


NVD link : CVE-2006-1372

Mitre link : CVE-2006-1372

CVE.ORG link : CVE-2006-1372


JSON object : View

Products Affected

benson_it_solutions

  • 1webcalendar