Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2243. PoCs published by Bl@ckbe@rD.
AI-analyzed exploit summary This exploit demonstrates both Cross-Site Scripting (XSS) and SQL Injection vulnerabilities in ASP Talk. The XSS exploit injects a JavaScript alert, while the SQL Injection exploit uses a UNION-based attack to extract data from the 'users' table.
Description
SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates both Cross-Site Scripting (XSS) and SQL Injection vulnerabilities in ASP Talk. The XSS exploit injects a JavaScript alert, while the SQL Injection exploit uses a UNION-based attack to extract data from the 'users' table.