CVE-2007-2621
Thyme Calendar 1.3 - SQL Injection via event_view.php eid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2621. PoCs published by warlord.
AI-analyzed exploit summary This is a detailed writeup describing a SQL injection vulnerability in Thyme Calendar 1.3, where the 'eid' parameter in event_view.php is not properly sanitized, allowing an attacker to extract user credentials via UNION-based SQLi.
Description
SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter.
Exploits (1)
This is a detailed writeup describing a SQL injection vulnerability in Thyme Calendar 1.3, where the 'eid' parameter in event_view.php is not properly sanitized, allowing an attacker to extract user credentials via UNION-based SQLi.