Description
Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by GulfTech Security · perlwebappsphp
https://www.exploit-db.com/exploits/1134
References (11)
Scores
EPSS
0.0148
EPSS Percentile
81.1%
Details
Status
published
Products (8)
mysql/eventum
1.1
mysql/eventum
1.2
mysql/eventum
1.2.2
mysql/eventum
1.3
mysql/eventum
1.3.1
mysql/eventum
1.4
mysql/eventum
1.5.4
mysql/eventum
1.5.5
Published
Dec 31, 2005
Tracked Since
Feb 18, 2026