Calendarix Multiple SQL Injection Vulnerabilities
BID:33752
Info
Calendarix Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 33752 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2009 12:00AM |
| Updated: | Feb 13 2009 10:48PM |
| Credit: | Jaykishan Nirmal |
| Vulnerable: |
Calendarix Calendarix Basic 0.8.20080808 Calendarix Calendarix Advanced 1.8.20081228 |
| Not Vulnerable: | |
Discussion
Calendarix Multiple SQL Injection Vulnerabilities
Calendarix is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect Calendarix Advanced 1.8.20081228 and Calendarix Basic 0.8.20080808; other versions may also be affected.
Calendarix is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect Calendarix Advanced 1.8.20081228 and Calendarix Basic 0.8.20080808; other versions may also be affected.
Exploit / POC
Calendarix Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Calendarix Multiple SQL Injection Vulnerabilities
Solution:
The vendor released updates to the Advanced version to address these issues. Please contact the vendor for information about fixes for the Basic version.
Solution:
The vendor released updates to the Advanced version to address these issues. Please contact the vendor for information about fixes for the Basic version.