CVE-2010-4795

JS Calendar (com_jscalendar) 1.5.1-1.5.4 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4795. PoCs published by Salvatore Fresta.

AI-analyzed exploit summary The document details SQL injection and XSS vulnerabilities in JS Calendar 1.5.1 for Joomla, providing technical analysis and sample exploit URLs. It lacks functional exploit code but includes specific technical details about the vulnerabilities.

Description

SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a details action to index.php. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Salvatore Fresta · textwebappsphp
https://www.exploit-db.com/exploits/15224

The document details SQL injection and XSS vulnerabilities in JS Calendar 1.5.1 for Joomla, providing technical analysis and sample exploit URLs. It lacks functional exploit code but includes specific technical details about the vulnerabilities.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Reliable
Target: JS Calendar 1.5.1 Joomla Component
No auth needed
Prerequisites: Access to the vulnerable Joomla component
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/43902
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/62379
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8223
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41766
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15224

Scores

EPSS 0.0115
EPSS Percentile 62.7%

Details

CWE
CWE-89
Status published
Products (2)
joomlaseller/com_jscalendar 1.5.1
joomlaseller/com_jscalendar 1.5.4
Published Apr 27, 2011
Tracked Since Feb 18, 2026