Back

CVE-2004-1552

SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
full_revolution aspwebcalendar 4.5

GitHub Security Advisory GHSA-9v8v-2gvj-6xgw

SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 4.08%

Top 10% most likely to be exploited

Threat Score 31.2 / 100

Data Sources

NVD EPSS GitHub