WebCalendar Multiple Module SQL Injection Vulnerabilities
BID:8540
Info
WebCalendar Multiple Module SQL Injection Vulnerabilities
| Bugtraq ID: | 8540 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2003 12:00AM |
| Updated: | Sep 03 2003 12:00AM |
| Credit: | Discovery is credited to noconflic <[email protected]>. |
| Vulnerable: |
WebCalendar WebCalendar 0.9.39 WebCalendar WebCalendar 0.9.38 WebCalendar WebCalendar 0.9.37 WebCalendar WebCalendar 0.9.36 WebCalendar WebCalendar 0.9.35 WebCalendar WebCalendar 0.9.33 WebCalendar WebCalendar 0.9.31 WebCalendar WebCalendar 0.9.30 WebCalendar WebCalendar 0.9.28 WebCalendar WebCalendar 0.9.24 WebCalendar WebCalendar 0.9.19 WebCalendar WebCalendar 0.9.8 k5n WebCalendar 0.9.43 k5n WebCalendar 0.9.41 k5n WebCalendar 0.9.40 k5n WebCalendar 0.9.34 k5n WebCalendar 0.9.32 k5n WebCalendar 0.9.29 k5n WebCalendar 0.9.27 k5n WebCalendar 0.9.26 k5n WebCalendar 0.9.25 k5n WebCalendar 0.9.23 k5n WebCalendar 0.9.22 k5n WebCalendar 0.9.21 k5n WebCalendar 0.9.20 k5n WebCalendar 0.9.16 k5n WebCalendar 0.9.15 k5n WebCalendar 0.9.11 |
| Not Vulnerable: | |
Exploit / POC
WebCalendar Multiple Module SQL Injection Vulnerabilities
The following proof of concept was provided:
http://www.example.com/webcalendar/view_m.php?id=additional sql command
http://www.example.com/webcalendar/login.php?user='additional%20sqlcommand
http://www.example.com/webcalendar/login.php?password='additional%20sql%20command
The following proof of concept was provided:
http://www.example.com/webcalendar/view_m.php?id=additional sql command
http://www.example.com/webcalendar/login.php?user='additional%20sqlcommand
http://www.example.com/webcalendar/login.php?password='additional%20sql%20command
Solution / Fix
WebCalendar Multiple Module SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WebCalendar Multiple Module SQL Injection Vulnerabilities
References:
References:
- WebCalendar (SourceForge)
- Webcalendar <= 0.9.42 Cross Site Scripting Attacks and Potential SQL Injection (noconflic
)