Back

CVE-2005-1397

SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Published: May 3, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
php-calendar php-calendar 0.1
php-calendar php-calendar 0.2
php-calendar php-calendar 0.3
php-calendar php-calendar 0.4
php-calendar php-calendar 0.5
php-calendar php-calendar 0.6
php-calendar php-calendar 0.7
php-calendar php-calendar 0.8
php-calendar php-calendar 0.9
php-calendar php-calendar 0.9.1
php-calendar php-calendar 0.10

GitHub Security Advisory GHSA-58gq-v2m7-vhq9

SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.81%

Top 23% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub