Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the SearchField parameter in a search action to (1) category_list.php, (2) Copy_of_calendar_list.php, (3) customer_statistics_list.php, (4) customer_list.php, and (5) task_statistics_list.php in the worldcalendar directory.
References
Configurations
History
21 Nov 2024, 01:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/fulldisclosure/2011-11/0305.html - Exploit | |
References | () http://osvdb.org/77244 - | |
References | () http://osvdb.org/77245 - | |
References | () http://osvdb.org/77246 - | |
References | () http://osvdb.org/77247 - | |
References | () http://osvdb.org/77248 - | |
References | () http://secunia.com/advisories/46970 - Vendor Advisory | |
References | () http://www.exploit-db.com/exploits/18127 - Exploit | |
References | () http://www.securityfocus.com/archive/1/520573/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/50733 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/71403 - |
Information
Published : 2012-08-23 20:55
Updated : 2025-04-11 00:51
NVD link : CVE-2011-5109
Mitre link : CVE-2011-5109
CVE.ORG link : CVE-2011-5109
JSON object : View
Products Affected
john_geo
- freelancer_calendar
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')