CVE-2010-4365

Harmistechnology Com Jeajaxeventcalendar - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php.

Exploits (2)

exploitdb WORKING POC
by ALTBTA · textwebappsphp
https://www.exploit-db.com/exploits/15610
exploitdb WRITEUP
by L0rd CrusAd3r · textwebappsphp
https://www.exploit-db.com/exploits/13997

References (4)

Core 4
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15610
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39836
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45050

Scores

EPSS 0.0013
EPSS Percentile 32.1%

Details

CWE
CWE-89
Status published
Products (1)
harmistechnology/com_jeajaxeventcalendar
Published Dec 01, 2010
Tracked Since Feb 18, 2026