[VIM] OSVDB 24021: 1WebCalendar viewEvent.cfm EventID Variable SQL Injection
jkouns at opensecurityfoundation.org
Thu Jan 4 00:30:26 EST 2007
Comment Official Statement from Benson IT Solutions (1/3/2007)
WebCalendar v4 has been updated to include fixes that filter the url
numeric and date variables in question and prevent non-numeric and
non-date values from being passed to the SQL queries. This fixes the
problems with the pages in question.
Guessing version 4.1 ?
More information about the VIM