CVE-2010-4795: SQL Injection
SQL injection vulnerability in the JS Calendar (comjscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the evid parameter in a details action to index.php. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4795?
CVE-2010-4795 is classified as a high severity vulnerability due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2010-4795?
To mitigate CVE-2010-4795, update the JS Calendar component to the latest version or remove the vulnerable component from your Joomla! installation.
What versions of JS Calendar are affected by CVE-2010-4795?
CVE-2010-4795 affects versions 1.5.1 and 1.5.4 of the JS Calendar component.
Can CVE-2010-4795 be exploited remotely?
Yes, CVE-2010-4795 allows remote attackers to execute arbitrary SQL commands, making it a remote exploitation risk.
What is the impact of CVE-2010-4795 on Joomla! sites?
The impact of CVE-2010-4795 on Joomla! sites includes unauthorized access to the database, potentially leading to data theft or manipulation.