Vulnerabilities > CVE-2007-3183 - Unspecified vulnerability in Vincent HOR Calendarix 0.7.20070307
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters to calendar.php and the (3) search string to cal_search.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Calendarix 0.7.20070307 Multiple SQL Injection Vulnerabilities. CVE-2007-3183. Webapps exploit for php platform |
id | EDB-ID:30234 |
last seen | 2016-02-03 |
modified | 2007-06-25 |
published | 2007-06-25 |
reporter | Jesper Jurcenoks |
source | https://www.exploit-db.com/download/30234/ |
title | Calendarix 0.7.20070307 - Multiple SQL Injection Vulnerabilities |
Nessus
NASL family | CGI abuses |
NASL id | CALENDARIX_MONTH_SQL_INJECTION.NASL |
description | The remote host is running Calendarix, a free web-based calendar application written in PHP. The version of Calendarix installed on the remote host fails to sanitize input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25567 |
published | 2007-06-26 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25567 |
title | Calendarix calendar.php Multiple Parameter SQL Injection |
code |
|
References
- http://osvdb.org/35694
- http://osvdb.org/35694
- http://secunia.com/advisories/25795
- http://secunia.com/advisories/25795
- http://securityreason.com/securityalert/2837
- http://securityreason.com/securityalert/2837
- http://www.netvigilance.com/advisory0038
- http://www.netvigilance.com/advisory0038
- http://www.osvdb.org/35373
- http://www.osvdb.org/35373
- http://www.securityfocus.com/archive/1/472221/100/0/threaded
- http://www.securityfocus.com/archive/1/472221/100/0/threaded
- http://www.securityfocus.com/bid/24633
- http://www.securityfocus.com/bid/24633
- http://www.securitytracker.com/id?1018287
- http://www.securitytracker.com/id?1018287
- http://www.vupen.com/english/advisories/2007/2324
- http://www.vupen.com/english/advisories/2007/2324
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35046
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35046