VYPR

Aspwebcalendar

by Fullrevolution

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2004-15520.030.04Dec 31, 2004SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.
CVE-2009-12230.000.00Apr 2, 2009aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb.