5
CVSSv2

CVE-2006-1422

Published: 28/03/2006 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and previous versions allows remote malicious users to execute arbitrary SQL commands via the event_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

jjwwebdesign phpbookingcalendar

Exploits

# Portal :PHP Booking Calendar 10 d (sql/upload) Exploit # Modified 2008 # Download : sourceforgenet/project/showfilesphp?group_id=132702 # exploit aported password crypted ######################################## #[*] Founded & Exploited by : Stack #[*] Contact: Ev!L =>> see down #[*] Greetz : Houssamix & Djekmani &amp ...
PoC by undefined1_ @ bash-xnet/undef/ phpBookingCalendar <= 10c "A PHP/MySQL Booking Calendar Application" wwwjjwdesigncom/booking_calendarhtml phpBookingCalendar is prone to a sql injection attack the sql injection works regardless of any magic_quotes_gpc settings wwwsitecom/details_viewphp?event_id=1 and 1=0 union all selec ...