CVE-2006-5977
Last modified
CVE-2006-5977 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in MultiCalendars allow remote attackers to execute arbitrary SQL commands via the (1) M or (2) Y parameter to rss_out.asp, or the (3) cate parameter to all_calendars.asp. NOTE: the all_calendars.asp/calsids vector is already covered by CVE-2006-2293.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in MultiCalendars allow remote attackers to execute arbitrary SQL commands via the (1) M or (2) Y parameter to rss_out.asp, or the (3) cate parameter to all_calendars.asp. NOTE: the all_calendars.asp/calsids vector is already covered by CVE-2006-2293.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Expinion.Net | Multicalendars | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5977?
How severe is CVE-2006-5977?
How do I fix CVE-2006-5977?
Are you affected by CVE-2006-5977?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
