发布时间 :2006-03-20 21:06:00
修订时间 :2017-07-19 21:30:30

[原文]SQL injection vulnerability in events.php in Maian Events 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.

[CNNVD]Maian Events eventsphp SQL注入漏洞(CNNVD-200603-339)

        Maian Events 1.0的eventsphp中的SQL注入漏洞,可让远程攻击者通过(1) month和(2) year参数执行任意SQL命令。

- CVSS (基础分值)

CVSS分值: 7.5 [严重(HIGH)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CPE (受影响的平台与产品)


- OVAL (用于检测的技术细节)


- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  BUGTRAQ  20060328 [eVuln] Maian Events SQL Injection Vulnerability
(UNKNOWN)  VUPEN  ADV-2006-0993
(UNKNOWN)  XF  maianevents-events-sql-injection(25298)

- 漏洞信息

Maian Events eventsphp SQL注入漏洞
高危 SQL注入
2006-03-20 00:00:00 2006-03-23 00:00:00
        Maian Events 1.0的eventsphp中的SQL注入漏洞,可让远程攻击者通过(1) month和(2) year参数执行任意SQL命令。

- 公告与补丁


- 漏洞信息 (F45077)

EV0102.txt (PacketStormID:F45077)
2006-04-01 00:00:00
Aliaksandr Hartsuyeu
exploit,sql injection

Maian Events version 1.0 suffers from a SQL injection flaw.

New eVuln Advisory:
Maian Events SQL Injection Vulnerability

eVuln ID: EV0102
CVE: CVE-2006-1341
Software: Maian Events
Sowtware's Web Site:
Versions: 1.0
Critical Level: Moderate
Type: SQL Injection
Class: Remote
Status: Unpatched. Developer(s) contacted.
PoC/Exploit: Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (

Vulnerable script: events.php

Parameters month, year are not properly sanitized before being used in SQL queries. This can be used to make any SQL query by injecting arbitrary SQL code.

Condition: magic_quotes_gpc = off

Available at:

http://[host]/menu.php?month=4&year=2006% 20or%201/*

No Patch available.

Discovered by: Aliaksandr Hartsuyeu (

Aliaksandr Hartsuyeu - Penetration Testing Services

- 漏洞信息

Maian Events events.php Multiple Parameter SQL Injection
Remote / Network Access Information Disclosure, Input Manipulation
Loss of Confidentiality, Loss of Integrity

- 漏洞描述

Maian Events contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the events.php script not properly sanitizing user-supplied input to the 'month' or 'year' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.

- 时间线

2006-03-16 Unknow
Unknow Unknow

- 解决方案

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

- 相关参考

- 漏洞作者