vendor:
Calendar Event
by:
Salvatore Fresta aka Drosophila
7,5
CVSS
HIGH
SQL Injection and Multiple Reflected XSS
89, 79
CWE
Product Name: Calendar Event
Affected Version From: 1.5.1
Affected Version To: 1.5.1
Patch Exists: NO
Related CWE: N/A
CPE: joomla:jscalendar
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla!
2010
JS Calendar 1.5.1 Joomla Component Multiple Remote Vulnerabilities
Input passed to the 'ev_id', 'month' and 'year' parameters are not properly sanitised before being used in SQL queries or returned to the user. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code or execute arbitrary HTML and script code in a users browser session in context of an affected site.
Mitigation:
No fix.