PublicDate: 2005-12-01 06:03:00 UTC Candidate: CVE-2005-3949 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3949 Description: Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php, and (4) multiple parameters to export_handler.php. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_webcalendar: released (1.0.2-2.1) edgy_webcalendar: released (1.0.2-2.1) feisty_webcalendar: DNE devel_webcalendar: released (1.0.2-2.1) upstream_webcalendar: needs-triage