Security Corporation reported an input validation vulnerability in Invision Power Board in the 'sources/calendar.php' file. A remote user can inject SQL commands.

It is reported that a remote user can submit a specially crafted series of requests to execute SQL commands on the underlying database.

Patch available at:

http://forums.invisionpower.com/index.php?...ST&f=1&t=108786

Enjoy