CVE-2009-1316
Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.
Date published : 2009-04-17
http://www.securityfocus.com/bid/34512
http://www.securityfocus.com/archive/1/502670/100/0/threaded