Required CVE Record Information
Description
Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid parameter. NOTE: this might be a duplicate of CVE-2005-4009.c.
References 4 Total
- securityreason.com: 1089 third-party-advisory
- vupen.com: ADV-2006-2220 vdb-entry
- securityfocus.com: 20060607 Calendar Express 2 SQL injection mailing-list
- securityfocus.com: 18314 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- securityreason.com: 1089 third-party-advisoryx_transferred
- vupen.com: ADV-2006-2220 vdb-entryx_transferred
- securityfocus.com: 20060607 Calendar Express 2 SQL injection mailing-listx_transferred
- securityfocus.com: 18314 vdb-entryx_transferred