CVE-2008-1344 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in a dayview action to plugins/calendar/calendar_backend.php and the (2) page parameter to ajaxp_backend.php.
Reference
http://secunia.com/advisories/29373 http://www.securityfocus.com/archive/1/489678/100/0/threaded http://www.securityfocus.com/bid/28232 https://exchange.xforce.ibmcloud.com/vulnerabilities/41179 https://www.exploit-db.com/exploits/5246
Share on: