vendor:
EasyCalendar
by:
JosS
7.5
CVSS
HIGH
Multiple Remote Vulnerabilities
89, 89, 79
CWE
Product Name: EasyCalendar
Affected Version From: 4.0tr
Affected Version To: 4.0tr
Patch Exists: Yes
Related CWE: N/A
CPE: a:myiosoft:easycalendar
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: localhost
2008
EasyCalendar <= 4.0tr - Multiple Remote Vulnerabilities
EasyCalendar is vulnerable to multiple remote vulnerabilities including SQL Injection, Blind SQL Injection and Cross Site Scripting. The SQL Injection vulnerability exists in the calendar_backend.php file and can be exploited by sending a maliciously crafted HTTP request to the vulnerable server. The Blind SQL Injection vulnerability exists in the ajaxp_backend.php file and can be exploited by sending a maliciously crafted HTTP request to the vulnerable server. The Cross Site Scripting vulnerability exists in the calendar_backend.php file and can be exploited by sending a maliciously crafted HTTP request to the vulnerable server.
Mitigation:
The vendor has released a patch to address these vulnerabilities. Users should upgrade to the latest version of EasyCalendar.