"value":"Multiple SQL injection vulnerabilities in MultiCalendars allow remote attackers to execute arbitrary SQL commands via the (1) M or (2) Y parameter to rss_out.asp, or the (3) cate parameter to all_calendars.asp. NOTE: the all_calendars.asp/calsids vector is already covered by CVE-2006-2293."
},
{
"lang":"es",
"value":"M\u00faltiples vulnerabilidades de inyeci\u00f3n SQL en MultiCalendars permiten a atacantes remotos ejecutar comandos SQL de su elecci\u00f3n a trav\u00e9s de los par\u00e1metros (1) M o (2) Y de rss_out.asp, o el par\u00e1metro (3) cate de all_calendars.asp. NOTA: el vector all_calendars.asp/calsids ya ha sido tratado por CVE-2006-2293."