CVE-2011-5109

Freelancer Calendar < 1.01 - SQL Injection via SearchField Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-5109. PoCs published by muuratsalo.

AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Freelancer Calendar <= 1.0.1, detailing affected endpoints and parameters. It includes a disclosure timeline and proof-of-concept URLs but lacks executable exploit code.

Description

Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the SearchField parameter in a search action to (1) category_list.php, (2) Copy_of_calendar_list.php, (3) customer_statistics_list.php, (4) customer_list.php, and (5) task_statistics_list.php in the worldcalendar directory.

Exploits (1)

exploitdb WRITEUP
by muuratsalo · textwebappsphp
https://www.exploit-db.com/exploits/18127

The provided text describes a SQL injection vulnerability in Freelancer Calendar <= 1.0.1, detailing affected endpoints and parameters. It includes a disclosure timeline and proof-of-concept URLs but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Freelancer Calendar <= 1.0.1
Auth required
Prerequisites: Registered account on the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77248
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77244
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77246
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46970
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/520573/100/0/threaded
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18127
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50733
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77247
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77245
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71403

Scores

EPSS 0.0204
EPSS Percentile 78.6%

Details

CWE
CWE-89
Status published
Products (1)
john_geo/freelancer_calendar < 1.01
Published Aug 23, 2012
Tracked Since Feb 18, 2026