← Zuruck zu CVEs
CVE-2006-2797
N/ABeschreibung
Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4) EventLocationID parameter in (f) delAddress.php; and (5) LocationID parameter in (g) delCategory.php.
CVE Details
CVSS v3.1 BewertungN/A
Veroffentlicht6/3/2006
Zuletzt geandert4/16/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
phpcommunitycalendar:phpcommunitycalendar
Referenzen
https://exchange.xforce.ibmcloud.com/vulnerabilities/26648(cve@mitre.org)
https://www.exploit-db.com/exploits/1818(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26648(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/1818(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.