7.5
CVSSv2

CVE-2003-0735

Published: 20/10/2003 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and previous versions allows remote malicious users to execute arbitrary SQL queries, as demonstrated using the year parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpwebsite phpwebsite

Exploits

source: wwwsecurityfocuscom/bid/8390/info Multiple SQL injection vulnerabilities have been reported in PHP Website These issue may be exploited by sending a malicious request to the calendar script Possible consequencs of exploitation include compromise of the site and disclosure of sensitive information wwwexamplecom/[PATH]/ ...