Vulnerabilities > Mxmania > Calendar MX Basic

DATE CVE VULNERABILITY TITLE RISK
2006-12-29 CVE-2006-6825 Information Disclosure vulnerability in Calendar MX BASIC
Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for calendar.mdb.
network
low complexity
mxmania
7.5
2006-12-28 CVE-2006-6792 SQL Injection vulnerability in Calendar MX Basic Calendar_Detail.ASP
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
network
low complexity
mxmania
7.5