CVE-2009-4973

Publication date

2010-07-27 18:39:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.