Multiple SQL injection vulnerabilities in Aaron Outpost ASP Inline Corporate Calendar allow remote attackers to execute arbitrary SQL commands via the Event_ID parameter to (1) defer.asp or (2) details.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asp_inline_corporate_calendar | Aaronoutpost | 3 (including) | 3 (including) |