CVE-2007-3519

phpEventCalendar < 0.2.3 - SQL Injection via eventdisplay.php id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-3519. PoCs published by AtT4CKxT3rR0r1ST, Iron.

AI-analyzed exploit summary The exploit demonstrates SQL injection (classic and blind), CSRF for admin addition, and XSS vulnerabilities in phpEventCalendar v0.2.3. It includes proof-of-concept URLs and a form for CSRF exploitation.

Description

SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/26408

The exploit demonstrates SQL injection (classic and blind), CSRF for admin addition, and XSS vulnerabilities in phpEventCalendar v0.2.3. It includes proof-of-concept URLs and a form for CSRF exploitation.

Classification
Working Poc 95%
Attack Type
Sqli | Xss | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: phpEventCalendar v0.2.3
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Iron · perlwebappsphp
https://www.exploit-db.com/exploits/4135

This exploit targets a SQL injection vulnerability in phpEventCalendar <= v0.2.3. It retrieves the username and password of a specified user ID by injecting a UNION-based SQL query into the 'id' parameter of eventdisplay.php.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: phpEventCalendar <= v0.2.3
No auth needed
Prerequisites: Target URL with vulnerable phpEventCalendar installation · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25915
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24721
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4135
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35193
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36338
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2404

Scores

EPSS 0.0123
EPSS Percentile 64.9%

Details

Status published
Products (1)
wesmo/phpeventcalendar < 0.2.3
Published Jul 03, 2007
Tracked Since Feb 18, 2026