First published: Tue Jan 13 2015(Updated: )
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Event Booking Calendar | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-10015 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2014-10015, update PHPJabbers Event Booking Calendar to the latest version that addresses this SQL injection vulnerability.
CVE-2014-10015 specifically affects PHPJabbers Event Booking Calendar version 2.0.
Yes, CVE-2014-10015 can allow remote attackers to execute arbitrary SQL commands, which could lead to data compromise.
Yes, CVE-2014-10015 is a publicly known vulnerability that has been documented in various security advisories.