CVE-2008-6038

MapCal 0.1 - SQL Injection via id Parameter in editevent Action

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6038. PoCs published by 0x90.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in MapCal 0.1 by injecting a UNION-based query to extract database information. The payload retrieves the database name and version through a crafted URL parameter.

Description

SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action, possibly related to dsp_editevent.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by 0x90 · textwebappsphp
https://www.exploit-db.com/exploits/32403

This exploit demonstrates an SQL injection vulnerability in MapCal 0.1 by injecting a UNION-based query to extract database information. The payload retrieves the database name and version through a crafted URL parameter.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: MapCal 0.1
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2647
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31304
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/496576/100/0/threaded

Scores

EPSS 0.0097
EPSS Percentile 57.3%

Details

CWE
CWE-89
Status published
Products (1)
mapcal/mapcal 0.1
Published Feb 03, 2009
Tracked Since Feb 18, 2026