PHP Event Calendar是开源的一个基于 AJAX 的多用户现代事件日历。它易于集成和完全可定制。 PHP Event Calendar 1.0版本存在SQL注入漏洞,该漏洞源于process.php 的 regConfirm/regDelete 函数存在安全问题,通过参数 userId 导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Event Calendar | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-6016 | 6.3 MEDIUM | itsourcecode Online Laundry Management System admin_class.php sql injection |
| CVE-2024-6015 | 6.3 MEDIUM | itsourcecode Online House Rental System manage_user.php sql injection |
| CVE-2024-6014 | 6.3 MEDIUM | itsourcecode Document Management System edithis.php sql injection |
| CVE-2024-6013 | 6.3 MEDIUM | itsourcecode Online Book Store admin_delete.php sql injection |
| CVE-2024-6008 | 6.3 MEDIUM | itsourcecode Online Book Store edit_book.php sql injection |
No comments yet