First published: Tue Mar 02 2010(Updated: )
SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an event action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
harmistechnology com jeeventcalendar | =1.0 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0795 is classified as a medium severity SQL injection vulnerability.
To fix CVE-2010-0795, update to a patched version of the JE Event Calendars component from Harmis Technology.
CVE-2010-0795 can allow remote attackers to execute arbitrary SQL commands on the vulnerable Joomla! site.
CVE-2010-0795 affects version 1.0 of the JE Event Calendars component.
CVE-2010-0795 specifically affects Joomla! installations using the vulnerable version of the JE Event Calendars component.