web2Project 'calendar.php' SQL Injection Vulnerability
BID:47539
Info
web2Project 'calendar.php' SQL Injection Vulnerability
| Bugtraq ID: | 47539 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 21 2011 12:00AM |
| Updated: | Apr 21 2011 12:00AM |
| Credit: | AutoSec Tools |
| Vulnerable: |
web2Project web2Project 2.3 |
| Not Vulnerable: | |
Discussion
web2Project 'calendar.php' SQL Injection Vulnerability
web2Project is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
web2Project 2.3 is affected; other versions may also be vulnerable.
web2Project is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
web2Project 2.3 is affected; other versions may also be vulnerable.
References
web2Project 'calendar.php' SQL Injection Vulnerability
References:
References:
- web2Project Homepage (web2Project)