Back

CVE-2004-1654

SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.

Published: Sep 1, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
phpwebsite phpwebsite 0.7.3
phpwebsite phpwebsite 0.8.2
phpwebsite phpwebsite 0.8.3
phpwebsite phpwebsite 0.9.3
phpwebsite phpwebsite 0.9.3.4

GitHub Security Advisory GHSA-v6wh-fw29-g4mg

SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.33%

Top 31% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub