CVE-2007-5187

Php-fusion Expanded Calendar Module - SQL Injection

Title source: rule

Description

SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the sel parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Matrix86 · phpwebappsphp
https://www.exploit-db.com/exploits/4475

Scores

EPSS 0.0066
EPSS Percentile 71.1%

Details

CWE
CWE-89
Status published
Products (1)
php-fusion/expanded_calendar_module 2.01
Published Oct 03, 2007
Tracked Since Feb 18, 2026