CVE-2009-4973 Information

Description

SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.

Reference

http://www.exploit-db.com/exploits/9524

Share on: