Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m2x-mm2c-xh64

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_report_handler.php. NOTE: the startid/activity_log.php vector is already covered by CVE-2005-3949.

SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_report_handler.php. NOTE: the startid/activity_log.php vector is already covered by CVE-2005-3949.

EPSS

Процентиль: 74%
0.00862
Низкий

Дефекты

CWE-89

Связанные уязвимости

ubuntu
почти 20 лет назад

SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_report_handler.php. NOTE: the startid/activity_log.php vector is already covered by CVE-2005-3949.

nvd
почти 20 лет назад

SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_report_handler.php. NOTE: the startid/activity_log.php vector is already covered by CVE-2005-3949.

debian
почти 20 лет назад

SQL injection vulnerability in WebCalendar 1.0.1 allows remote attacke ...

EPSS

Процентиль: 74%
0.00862
Низкий

Дефекты

CWE-89