SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2003-0726
http://www.kb.cert.org/vuls/id/925166