VYPR

Calendar Mx Basic

by Mxmania

CVEs (2)

  • CVE-2006-6792Dec 28, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2006-6825Dec 29, 2006
    risk 0.00cvss epss 0.01

    Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for calendar.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.