Back

CVE-2006-0252

SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters.

Published: Jan 18, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
benders_calendar benders_calendar *

GitHub Security Advisory GHSA-3jph-25vj-7g8w

SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.55%

Top 27% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub