cpe:/a:duware:ducalendar:1.0 CVE-2008-2868 2008-06-26T13:41:00.000-04:00 2017-09-28T21:31:22.647-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2008-06-26T15:07:00.000-04:00 ALLOWS_OTHER_ACCESS SECTRACK 1020358 BID 29919 SECUNIA 30774 EXPLOIT-DB 5927 VUPEN ADV-2008-1924 XF ducalendar-detail-sql-injection(43325) SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.