13 lines
No EOL
738 B
Text
13 lines
No EOL
738 B
Text
source: https://www.securityfocus.com/bid/15662/info
|
|
|
|
WebCalendar is prone to multiple SQL injection vulnerabilities.
|
|
|
|
This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
|
|
|
|
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
|
|
|
|
Version 1.0.1. is vulnerable; other versions may also be affected.
|
|
|
|
http://www.example.com/webcalendar/activity_log.php?startid=%2527
|
|
http://www.example.com/webcalendar/activity_log.php?startid=%27
|
|
http://www.example.com/webcalendar/activity_log.php?startid=' |