Description
|
|
Multiple vulnerabilities were identified in Calendarix Advanced, which may be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to an input validation error in the "cal_day.php", "cal_pophols.php", "calendar.php", "cal_week.php" and "cal_cat.php" scripts when handling specially crafted "catview", "id" and "year" parameters, which may be exploited by a remote attacker to cause arbitrary SQL commands to be executed.
|