Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6158. PoCs published by JosS.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Proverbs Web Calendar 1.1 by injecting a malformed password input to bypass authentication. The payload manipulates the SQL query to potentially allow unauthorized access.
Description
Multiple SQL injection vulnerabilities in caladmin.inc.php in Proverbs Web Calendar 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) loginname (aka Username) and (2) loginpass (aka Password) parameters to caladmin.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Proverbs Web Calendar 1.1 by injecting a malformed password input to bypass authentication. The payload manipulates the SQL query to potentially allow unauthorized access.