EIP-2026-105051

PRE-CVE

Ajax Availability Calendar 3.x - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105051. PoCs published by AtT4CKxT3rR0r1ST.

AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Ajax Availability Calendar 3.X.X, including SQL injection, reflected XSS, full path disclosure, and CSRF. The SQL injection PoC extracts admin credentials via a union-based attack, while other sections outline XSS and CSRF attack vectors.

Description

Ajax Availability Calendar 3.x - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/25409

This exploit demonstrates multiple vulnerabilities in Ajax Availability Calendar 3.X.X, including SQL injection, reflected XSS, full path disclosure, and CSRF. The SQL injection PoC extracts admin credentials via a union-based attack, while other sections outline XSS and CSRF attack vectors.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Ajax Availability Calendar 3.X.X
No auth needed
Prerequisites: Target URL with vulnerable parameter
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026