Lucene search

K
cveMitreCVE-2004-0275
HistoryNov 23, 2004 - 5:00 a.m.

CVE-2004-0275

2004-11-2305:00:00
mitre
web.nvd.nist.gov
24
cve-2004-0275
sql injection
bosdates
calendar_download.php
information security
vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.7

Confidence

Low

EPSS

0.002

Percentile

61.9%

SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.

Affected configurations

Nvd
Node
bosdevbosdatesMatch3.0
OR
bosdevbosdatesMatch3.1
OR
bosdevbosdatesMatch3.2
VendorProductVersionCPE
bosdevbosdates3.0cpe:2.3:a:bosdev:bosdates:3.0:*:*:*:*:*:*:*
bosdevbosdates3.1cpe:2.3:a:bosdev:bosdates:3.1:*:*:*:*:*:*:*
bosdevbosdates3.2cpe:2.3:a:bosdev:bosdates:3.2:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.7

Confidence

Low

EPSS

0.002

Percentile

61.9%

Related for CVE-2004-0275