Security Corporation reported an input validation vulnerability in Invision Power Board in the 'sources/calendar.php' file. A remote user can inject SQL commands.
It is reported that a remote user can submit a specially crafted series of requests to execute SQL commands on the underlying database.
Patch available at:
http://forums.invisionpower.com/index.php?...ST&f=1&t=108786
Enjoy