First published: Mon Jun 28 2010(Updated: )
SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
harmistechnology com jeajaxeventcalendar | =1.0.5 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2513 is considered a critical SQL injection vulnerability that can allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2010-2513, upgrade the JE Ajax Event Calendar component to a version that is not vulnerable.
CVE-2010-2513 affects the JE Ajax Event Calendar component version 1.0.5 for Joomla!.
Exploiting CVE-2010-2513 could lead to unauthorized access to the database, data manipulation, and extraction of sensitive information.
Yes, if your Joomla! site is using the vulnerable JE Ajax Event Calendar component version 1.0.5, it is at risk from CVE-2010-2513.