Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2868. PoCs published by Bl@ckbe@rD.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in DUcalendar v1.0 via the 'iEve' parameter in detail.asp. It includes payloads for both MS SQL Server and MS Access, allowing unauthorized database queries.
Description
SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in DUcalendar v1.0 via the 'iEve' parameter in detail.asp. It includes payloads for both MS SQL Server and MS Access, allowing unauthorized database queries.