|
Description
|
|
Two vulnerabilities were identified in Calendarix, which could be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to input validation errors in the "cal_login.php" and "cal_day.php" scripts that do not properly validate the "login" and "catview" parameters before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.
|