CVE-2008-3452
eNdonesia Calendar module - SQL Injection via loc_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3452. PoCs published by Jack.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in eNdonesia 8.4's calendar module. It crafts a malicious SQL query to extract user credentials (username and password) from the 'authors' table via a UNION-based attack.
Description
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the loc_id parameter in a list_events action to mod.php.
Exploits (1)
This exploit targets a SQL injection vulnerability in eNdonesia 8.4's calendar module. It crafts a malicious SQL query to extract user credentials (username and password) from the 'authors' table via a UNION-based attack.