Back
CVE-2005-1397
SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
Published: May 3, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (11)
| Vendor | Product | Version |
|---|---|---|
| php-calendar | php-calendar | 0.1 |
| php-calendar | php-calendar | 0.2 |
| php-calendar | php-calendar | 0.3 |
| php-calendar | php-calendar | 0.4 |
| php-calendar | php-calendar | 0.5 |
| php-calendar | php-calendar | 0.6 |
| php-calendar | php-calendar | 0.7 |
| php-calendar | php-calendar | 0.8 |
| php-calendar | php-calendar | 0.9 |
| php-calendar | php-calendar | 0.9.1 |
| php-calendar | php-calendar | 0.10 |
GitHub Security Advisory GHSA-58gq-v2m7-vhq9
SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers...
References (12)
- http://secunia.com/advisories/15116 Patch
- http://sourceforge.net/project/shownotes.php?release_id=323483
- http://www.osvdb.org/15866
- http://www.securityfocus.com/bid/13405 Patch
- http://www.vupen.com/english/advisories/2005/0418
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20297
- http://secunia.com/advisories/15116 Patch
- http://sourceforge.net/project/shownotes.php?release_id=323483
- http://www.osvdb.org/15866
- http://www.securityfocus.com/bid/13405 Patch
- http://www.vupen.com/english/advisories/2005/0418
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20297
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.81%
Top 23% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub