CVE-2008-6038 Information

Description

SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action possibly related to dsp_editevent.php.

Reference

http://0x90.com.ar/Advisory/20080920-2.txt http://www.securityfocus.com/archive/1/496576/100/0/threaded http://www.securityfocus.com/bid/31304 http://www.vupen.com/english/advisories/2008/2647

Share on: