SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter.  NOTE: the affected version has been disputed by the vendor.  It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2006-04-25 12:50
Updated : 2018-10-18 16:37
NVD link : CVE-2006-2018
Mitre link : CVE-2006-2018
CVE.ORG link : CVE-2006-2018
JSON object : View
Products Affected
                jelsoft
- vbulletin
 
CWE
                