CVE-2005-4008: SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL co
infovulnerability
security
Summary
Jax Calendar version 1.34 contains a SQL injection vulnerability (a type of attack where an attacker inserts malicious SQL code into input fields) in the jax_calendar.php file. The vulnerability allows remote attackers to execute arbitrary SQL commands through the cal_id parameter and possibly the Y and m parameters.
Vulnerability Details
CVSS Score
7.5
EPSS (30-day exploit probability)
EPSS: 0.6%
Classification
Attack SophisticationTrivial
Original source: https://nvd.nist.gov/vuln/detail/CVE-2005-4008
First tracked: February 15, 2026 at 08:42 PM
Classified by LLM (prompt v3) · confidence: 95%