Vulnerabilities > CVE-2007-3515 - SQL Injection vulnerability in TotalCalendar View_Event Script

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
sweetphp
critical
exploit available

Summary

SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Vulnerable Configurations

Part Description Count
Application
Sweetphp
1

Exploit-Db

descriptionTotalCalendar <= 2.402 (view_event.php) Remote SQL Injection Vulns. CVE-2007-3515. Webapps exploit for php platform
fileexploits/php/webapps/4130.txt
idEDB-ID:4130
last seen2016-01-31
modified2007-06-30
platformphp
port
published2007-06-30
reportert0pP8uZz
sourcehttps://www.exploit-db.com/download/4130/
titleTotalCalendar <= 2.402 view_event.php Remote SQL Injection Vulns
typewebapps