vendor:
Web Calendar
by:
t0pP8uZz
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Web Calendar
Affected Version From: Web Calendar <= 4.1
Affected Version To: Web Calendar <= 4.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: ActivePerl
2008
Web Calendar <= 4.1 Blind SQL Injection Exploit
Web Calendar suffers from a insecure mysql query which allows an attacker to inject malicious SQL queries and gain access to sensitive information such as login credentials. This exploit was discovered and coded by t0pP8uZz on 24 April 2008 and tested in ActivePerl.
Mitigation:
The vendor has not been notified and no patch exists for this vulnerability.