Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-03-24T02:00:00

Updated: 2017-07-19T15:57:01

Reserved: 2006-03-23T00:00:00


Link: CVE-2006-1372

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-03-24T02:02:00.000

Modified: 2017-07-20T01:30:32.317


Link: CVE-2006-1372

JSON object: View

cve-icon Redhat Information

No data.