SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters.
Link | Tags |
---|---|
http://secunia.com/advisories/18462 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/422052/100/0/threaded | mailing list |
http://www.osvdb.org/22449 | vdb entry |
http://securitytracker.com/id?1015491 | vendor advisory vdb entry exploit |
http://www.vupen.com/english/advisories/2006/0190 | vdb entry |
http://www.securityfocus.com/bid/16242 | vdb entry vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24120 | vdb entry |
http://evuln.com/vulns/30/summary.html | vendor advisory exploit |