Back
CVE-2004-1787
SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| postnuke_software_foundation | postcalendar | 4.0.0 |
GitHub Security Advisory GHSA-xpp9-cvrv-9rvf
SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary...
References (12)
- http://news.postnuke.com/modules.php?op=modload&name=News&file=article&sid=2537 Patch
- http://secunia.com/advisories/10554 Patch
- http://securitytracker.com/id?1008621 Patch
- http://www.osvdb.org/3336
- http://www.securityfocus.com/bid/9372 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14111
- http://news.postnuke.com/modules.php?op=modload&name=News&file=article&sid=2537 Patch
- http://secunia.com/advisories/10554 Patch
- http://securitytracker.com/id?1008621 Patch
- http://www.osvdb.org/3336
- http://www.securityfocus.com/bid/9372 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14111
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.33%
Top 31% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub