CVE-2004-1552
aspWebCalendar - SQL Injection via Username Field or EventID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2004-1552. PoCs published by Bl@ckbe@rD, parad0x.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass and XSS vulnerability in Web Calendar System v3.12/3.30. The SQL injection bypasses login authentication, while the XSS executes arbitrary JavaScript in the context of the victim's browser.
Description
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.
Exploits (2)
This exploit demonstrates an authentication bypass and XSS vulnerability in Web Calendar System v3.12/3.30. The SQL injection bypasses login authentication, while the XSS executes arbitrary JavaScript in the context of the victim's browser.
This exploit demonstrates a SQL injection vulnerability in aspWebCalendar. The PoC provides a URL with a crafted query to extract sensitive information (e.g., admin password) from the database.