Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2242. PoCs published by Bl@ckbe@rD.
AI-analyzed exploit summary This exploit demonstrates both Cross-Site Scripting (XSS) and SQL Injection vulnerabilities in ASP Talk. The XSS exploit injects a JavaScript alert, while the SQL Injection exploit uses a UNION-based attack to extract data from the 'users' table.
Description
SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the order parameter.
Exploits (1)
This exploit demonstrates both Cross-Site Scripting (XSS) and SQL Injection vulnerabilities in ASP Talk. The XSS exploit injects a JavaScript alert, while the SQL Injection exploit uses a UNION-based attack to extract data from the 'users' table.