Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1344. PoCs published by JosS.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in EasyCalendar <= 4.0tr, including SQL injection, blind SQL injection, and XSS. The PoC provides specific URLs and payloads to exploit these vulnerabilities.
Description
Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in a dayview action to plugins/calendar/calendar_backend.php and the (2) page parameter to ajaxp_backend.php.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in EasyCalendar <= 4.0tr, including SQL injection, blind SQL injection, and XSS. The PoC provides specific URLs and payloads to exploit these vulnerabilities.