Back

CVE-2005-4011

SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Published: Dec 5, 2005 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
codewalkers ltwcalendar *

GitHub Security Advisory GHSA-w9rg-rxp3-7v7q

SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.37%

Top 18% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub