.:[ packet storm ]:.
                               
trust nothing
trust nothing

 ///  File Name:secunia-calendarix.txt
Description:
Secunia Research has discovered two vulnerabilities in Calendarix Basic, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "catsearch" parameter in cal_search.php and "catview" in cal_cat.php is not properly sanitized before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Calendarix Basic 0.8.20071118 is affected.
Homepage:http://secunia.com/
File Size:4530
Related CVE(s):CVE-2008-2429
Last Modified:Aug 25 20:30:10 2008
MD5 Checksum:25805f56ddb5ea080e60cc240a6e595d

 .:. Back