Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2009-1223
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb.
0
Attacker Value
Unknown
CVE-2008-2832
Disclosure Date: June 24, 2008 (last updated October 04, 2023)
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.
0
Attacker Value
Unknown
CVE-2004-1552
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.
0