VendorsCalogiccalogic_calendars1.2.2
Vulnerabilities

Calogic Calogic Calendars 1.2.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2006-2570
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLPath"] parameter to (1) reconfig.php and (2) srxclr.php. NOTE: this might be due to a globals overwrite issue.
Published 2006-05-24 · Modified
7.51 PoCEPSS 0.025
CVE-2008-2444
SQL injection vulnerability in userreg.php in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary SQL commands via the langsel parameter.
Published 2008-05-27 · Modified
7.51 PoCEPSS 0.010
CVE-2006-0180
Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the "Adding New Event" page, and possibly other vectors, involving iframe tags.
Published 2006-01-12 · Modified
4.3EPSS 0.014