CVE-2014-8586
CP Multi View Event Calendar 1.01 - SQL Injection via calid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2014-8586.
PoCs published by Claudio Viviani, Joaquin Ramirez Martinez, bperry, including Metasploit module auxiliary/scanner/http/wordpress_cp_calendar_sqli.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in CP Multi View Event Calendar 1.01 via the 'calid' parameter. It includes payloads for boolean-based blind, error-based, UNION query, and time-based blind SQL injection techniques.
Description
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in CP Multi View Event Calendar 1.01 via the 'calid' parameter. It includes payloads for boolean-based blind, error-based, UNION query, and time-based blind SQL injection techniques.
This Metasploit module scans for an unauthenticated SQL injection vulnerability in the WordPress CP Multi-View Calendar plugin v1.1.4. It uses a UNION-based SQLi technique to detect the vulnerability by injecting a payload into the 'id' parameter.