CVE-2005-3949
CVE-2005-3949
Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php, and (4) multiple parameters to export_handler.php.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://secunia.com/advisories/17784http://secunia.com/advisories/19240http://securityreason.com/securityalert/215https://exchange.xforce.ibmcloud.com/vulnerabilities/23369http://sourceforge.net/forum/forum.php?thread_id=1392833&forum_id=11587http://www.debian.org/security/2006/dsa-1002http://www.osvdb.org/21216http://www.osvdb.org/21217http://www.osvdb.org/21218http://www.osvdb.org/21219http://www.securityfocus.com/archive/1/417900/100/0/threadedhttp://www.securityfocus.com/archive/1/418286/100/0/threaded