Description - SQL Injection and Authentication Bypass in Calendarix
SQL Injection found in Calendarix script.
- Exploit
- Available
- Solution
- Not available - check vendor's website
Vulnerable scripts: cal_functions.inc.php admin/cal_login.php
Variables $catview(cal_functions.inc.php) $login(admin/cal_login.php) are not properly sanitized before being used in a SQL query. This can be used to make any SQL query by injecting arbitrary SQL code.
Authentication bypass is possible.
Condition for Authentication bypass: magic_quotes_gpc - off
Order Source Code Audit
Prevent attacks by source code audit of a site done by eVuln team.The work will be done by experts in web application security.


