1WebCalendar multiple scripts SQL injection
| 1webcalendar-multiple-sql-injection (25373) |
Description:
1WebCalendar is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the viewEvent.cfm using the 'EventID' parameter, to the News/newsView.cfm script using the 'NewsID' parameter or to the mainCal.cfm script using the 'ThisDate' parameter, which could allow the attacker to add, modify, or delete information in the back-end database.
Consequences:
Data Manipulation
Remedy:
Upgrade to the latest version of 1WebCalendar (4.1 or later), available from the 1WebCalendar Web site. See References.
References:
- 1WebCalendar Web site: 1WebCalendar v 4.0.
- UNSECURED SYSTEMS March 22,2006: 1WebCalendar v 4.x vuln..
- BID-17193: 1WebCalendar Multiple SQL Injection Vulnerabilities
- CVE-2006-1372: Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.
- OSVDB ID: 24021: 1WebCalendar viewEvent.cfm EventID Variable SQL Injection
- OSVDB ID: 24022: 1WebCalendar /news/newsView.cfm NewsID Variable SQL Injection
- OSVDB ID: 24023: 1WebCalendar mainCal.cfm SQL Injection
- SA19329: 1WebCalendar Multiple SQL Injection Vulnerabilities
- VUPEN/ADV-2006-1040: 1WebCalendar Multiple Parameter Handling Remote SQL Injection Vulnerabilities
Platforms Affected:
- Apple Mac OS X 10.3.9
- Apple Mac OS X 10.4.3
- Benson IT Solutions 1WebCalendar 4.0
- IBM AIX 5.1
- IBM AIX 5.3
- IBM AIX 5L
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2003 Server Web
- Microsoft Windows 2003 Server Enterprise
- Microsoft Windows 2003 Server Standard
- Microsoft Windows XP Professional
- Microsoft Windows XP Home
- RedHat Enterprise Linux 4 ES
- RedHat Enterprise Linux 4 AS
- Sun Solaris 10
- Sun Solaris 8
- Sun Solaris 9
- SuSE Linux Enterprise Server 8
- SuSE SuSE SLES 9
- Turbolinux Turbolinux 8 Server JA
Reported:
Mar 22, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
