7.5
CVSSv2

CVE-2007-5187

Published: 03/10/2007 Updated: 21/04/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote malicious users to execute arbitrary SQL commands via the sel parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php-fusion expanded calendar module 2.01

Exploits

<?php print_r(" /******************************************************** * Expanded Calendar 2x (PHP-Fusion module) * * User pass disclosure exploit * * Found by Matrix86 of Rbt-4 Crew * * Site: wwwrbt-4net * * Mail: info[at]rbt-4[dot]net ...