7.5
CVSSv2

CVE-2008-1344

Published: 17/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) year parameter in a dayview action to plugins/calendar/calendar_backend.php and the (2) page parameter to ajaxp_backend.php.

Vulnerable Product Search on Vulmon Subscribe to Product

myiosoft easycalendar 4.0tr

Exploits

--==+=================== Spanish Hackers Team (wwwspanish-hackerscom) =================+==-- --==+ EasyCalendar <= 40tr - Multiple Remote Vulnerabilities +==-- --==+====================================================================================+==-- [+] [JosS] + [Spanish Hackers Team] + [Sy ...