Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6104. PoCs published by r45c4l.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in A4Desk Event Calendar by injecting a UNION-based query to extract database version, name, and user information. The payload is appended to the 'eventid' parameter in the admin interface.
Description
SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via the eventid parameter to admin/index.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in A4Desk Event Calendar by injecting a UNION-based query to extract database version, name, and user information. The payload is appended to the 'eventid' parameter in the admin interface.