Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Sun, 27 May 2012 22:40:42 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1081044149&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0808-advisories%2Fsecunia-calendarix.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1081044149.1338158442.1338158442.1338158442.1%3B%2B__utmz%3D32867617.1338158442.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) secunia-calendarix.txt http://packetstormsecurity.org/files/69392/secunia-calendarix.txt http://packetstormsecurity.org/files/69392/secunia-calendarix.txt http://packetstormsecurity.org/files/69392/secunia-calendarix.txt.html Tue, 26 Aug 2008 00:30:10 GMT Secunia Research has discovered two vulnerabilities in Calendarix Basic, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "catsearch" parameter in cal_search.php and "catview" in cal_cat.php is not properly sanitized before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Calendarix Basic 0.8.20071118 is affected.