phpCommunityCalendar multiple scripts SQL injection
| phpcommunitycalendar-multiple-sql-injection (26648) |
Description:
phpCommunityCalendar is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the month.php, day.php, and delCalendar.php script using the 'CalendarDetailsID' parameter, to the event.php script using the 'ID' parameter, to the delAdmin.php script using the 'AdminUserID' parameter, to the delAddress.php script using the 'EventLocationID' parameter or to the delCategory.php script using the 'LocationID parameter', which could allow the attacker to view, add, modify, or delete information in the back-end database.
Platforms Affected:
- AppIdeas, phpCommunityCalendar 4.0.3
Remedy:
No remedy available as of July 4, 2009.
Consequences:
Data Manipulation
References:
- phpCommunityCalendar Web site, Open.AppIdeas.com - phpCommunityCalendar at http://open.appideas.com/Calendar/.
- CVE-2006-2797: Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4) EventLocationID parameter in (f) delAddress.php; and (5) LocationID parameter in (g) delCategory.php.
- CVE-2006-2798: Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php.
- OSVDB ID: 31691: phpCommunityCalendar week.php LoName Variable XSS
- OSVDB ID: 31692: phpCommunityCalendar month.php LoName Variable XSS
- OSVDB ID: 31693: phpCommunityCalendar event.php AddressLink Variable XSS
Reported:
May 23, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
