Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in Calendarix Basic 0.8.20071118 allow remote attackers to execute arbitrary SQL commands via (1) the catsearch parameter to cal_search.php or (2) the catview parameter to cal_cat.php. NOTE: vector 1 might overlap CVE-2007-3183.3, and vector 2 might overlap CVE-2005-1865.2.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Calendarix 'cal_search.php' SQL注入攻击漏洞
Vulnerability Description
Calendarix是运行在PHP和MySQL上的WEB日历系统。 Calendarix的cal_search.php文件中没有正确的验证对catsearch参数地输入,cal_cat.php文件中没有正确地过滤对catview参数的输入,远程攻击者可以通过SQL注入攻击检索管理员的用户名和口令哈希。
CVSS Information
N/A
Vulnerability Type
N/A