CVE-2009-4973
TotalCalendar 2.4 - SQL Injection via rss.php selectedCal Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4973. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates blind SQL injection (bSQL) and Local File Inclusion (LFI) vulnerabilities in TotalCalendar 2.4. The bSQL exploit targets the 'selectedCal' parameter in rss.php, while the LFI exploit targets the 'box' parameter in box_display.php.
Description
SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.
Exploits (1)
This exploit demonstrates blind SQL injection (bSQL) and Local File Inclusion (LFI) vulnerabilities in TotalCalendar 2.4. The bSQL exploit targets the 'selectedCal' parameter in rss.php, while the LFI exploit targets the 'box' parameter in box_display.php.