Vulnerabilities > CVE-2006-1372 - SQL Injection vulnerability in 1WebCalendar

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
benson-it-solutions
exploit available

Summary

Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.

Vulnerable Configurations

Part Description Count
Application
Benson_It_Solutions
1

Exploit-Db

  • description1WebCalendar 4.0 mainCal.cfm SQL Injection. CVE-2006-1372. Webapps exploit for cfm platform
    idEDB-ID:27457
    last seen2016-02-03
    modified2006-03-22
    published2006-03-22
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/27457/
    title1WebCalendar 4.0 mainCal.cfm SQL Injection
  • description1WebCalendar 4.0 /news/newsView.cfm NewsID Parameter SQL Injection. CVE-2006-1372. Webapps exploit for cfm platform
    idEDB-ID:27456
    last seen2016-02-03
    modified2006-03-22
    published2006-03-22
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/27456/
    title1WebCalendar 4.0 /news/newsView.cfm NewsID Parameter SQL Injection
  • description1WebCalendar 4.0 viewEvent.cfm EventID Parameter SQL Injection. CVE-2006-1372. Webapps exploit for cfm platform
    idEDB-ID:27455
    last seen2016-02-03
    modified2006-03-22
    published2006-03-22
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/27455/
    title1WebCalendar 4.0 - viewEvent.cfm EventID Parameter SQL Injection

Statements

contributorGreg Benson
lastmodified2007-01-03
organizationBenson Solutions
statementWebCalendar v4 has been updated to include fixes that filter the url numeric and date variables in question and prevent non-numeric and non-date values from being passed to the SQL queries. This fixes the problems with the pages in question. http://www.bensonitsolutions.com/Calendar/v4/