Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-113255. PoCs published by hyp3rlinx.
AI-analyzed exploit summary The exploit demonstrates a CSRF protection bypass in WebCalendar v1.2.7 by omitting the HTTP Referer header using a meta tag, allowing unauthorized password changes and access control modifications. Additionally, it details a PHP code injection vulnerability via the installation script's Database Cache Directory field, enabling arbitrary command execution.
Description
WebCalendar 1.2.7 - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates a CSRF protection bypass in WebCalendar v1.2.7 by omitting the HTTP Referer header using a meta tag, allowing unauthorized password changes and access control modifications. Additionally, it details a PHP code injection vulnerability via the installation script's Database Cache Directory field, enabling arbitrary command execution.