SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nuked-klan | Nuked-klan | * | 1.7.5 (including) |
Nuked-klan | Nuked-klan | 1.2 (including) | 1.2 (including) |
Nuked-klan | Nuked-klan | 1.2_beta (including) | 1.2_beta (including) |
Nuked-klan | Nuked-klan | 1.3 (including) | 1.3 (including) |
Nuked-klan | Nuked-klan | 1.3_beta (including) | 1.3_beta (including) |
Nuked-klan | Nuked-klan | 1.4 (including) | 1.4 (including) |
Nuked-klan | Nuked-klan | 1.5 (including) | 1.5 (including) |
Nuked-klan | Nuked-klan | 1.5_sp2 (including) | 1.5_sp2 (including) |
Nuked-klan | Nuked-klan | 1.7 (including) | 1.7 (including) |