CVE-2008-6038
MapCal 0.1 - SQL Injection via id Parameter in editevent Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6038. PoCs published by 0x90.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in MapCal 0.1 by injecting a UNION-based query to extract database information. The payload retrieves the database name and version through a crafted URL parameter.
Description
SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action, possibly related to dsp_editevent.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in MapCal 0.1 by injecting a UNION-based query to extract database information. The payload retrieves the database name and version through a crafted URL parameter.