CVE-2006-2264
Calendar Manager Pro 1.00 - SQL Injection via Date, SearchFor, or ID Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2006-2264. PoCs published by dj_eyes2005.
AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in Calendar Manager Pro due to insufficient input sanitization. It includes a generic example URL for SQL injection but lacks actual exploit code.
Description
Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to admin/edit.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (3)
The provided text describes SQL injection and XSS vulnerabilities in Calendar Manager Pro due to insufficient input sanitization. It includes a generic example URL for SQL injection but lacks actual exploit code.
The provided text describes SQL injection and XSS vulnerabilities in Calendar Manager Pro due to improper input sanitization. It includes a generic example URL for SQL injection but lacks actual exploit code.
The provided text describes SQL injection and XSS vulnerabilities in Calendar Manager Pro due to insufficient input sanitization. It includes a sample URL demonstrating the SQL injection vector but lacks executable exploit code.