VYPR

Multicalendars

by Expinion.net

CVEs (2)

  • CVE-2006-2293May 10, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

  • CVE-2006-5977Nov 20, 2006
    risk 0.00cvss epss 0.00

    Multiple SQL injection vulnerabilities in MultiCalendars allow remote attackers to execute arbitrary SQL commands via the (1) M or (2) Y parameter to rss_out.asp, or the (3) cate parameter to all_calendars.asp. NOTE: the all_calendars.asp/calsids vector is already covered by CVE-2006-2293.