Multiple Vulnerabilities in JS Calendar 1.5.1 and 1.5.4 for Joomla!
Joomla!® is a content management system with more than 200,000 users and contributors. JS Calendar is an enhanced calendar extension.
Affected Application: JS Calendar 1.5.1 and 1.5.4.
Issue: On 04/27/2011, cross-site scripting and SQL injection vulnerabilities were reported for the JS Calendar (com_jscalendar) component of Joomla! The vulnerabilities are in version 1.5.1 and 1.5.4, and let attackers execute SQL commands, steal cookie-based account information, or perform other malicious actions.
Resolution: No reported resolution exists for this vulnerability.
This information was compiled using information in the National Vulnerability Database. For more information about this issue, see the following summaries:
CVE-2010-4794
CVE-2010-4795
To learn more about cross-site scripting and SQL injection vulnerabilities, see Cross-Site Scripting and Injection Flaws.
Website Protection Site Scanner scans for this vulnerability, and many more. To learn about Site Scanner, see Getting Started with Website Protection Site Scanner.