7.5
CVE-2004-1552
- EPSS 4.08%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:55
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Full Revolution ≫ Aspwebcalendar Version4.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.08% | 0.894 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://marc.info/?l=bugtraq&m=109604910025090&w=2
http://secunia.com/advisories/12651
http://secunia.com/advisories/24622
http://www.securityfocus.com/bid/11246
http://www.securityfocus.com/bid/23098
http://www.vupen.com/english/advisories/2007/1093
https://exchange.xforce.ibmcloud.com/vulnerabilities/17506
https://exchange.xforce.ibmcloud.com/vulnerabilities/33157
https://www.exploit-db.com/exploits/3546