Vulnerabilities > Vincent HOR > Calendarix > 0.6.2005.08.30

DATE CVE VULNERABILITY TITLE RISK
2006-04-19 CVE-2006-1835 Cross-Site Scripting vulnerability in Calendarix YearCal.PHP
Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.
network
high complexity
vincent-hor
2.6
2006-02-01 CVE-2006-0492 SQL Injection vulnerability in Vincent HOR Calendarix 0.6.20050830
Multiple SQL injection vulnerabilities in Calendarix allow remote attackers to execute arbitrary SQL commands via (1) the catview parameter in cal_functions.inc.php and (2) the login parameter in cal_login.php.
network
low complexity
vincent-hor
7.5