VendorsHarmis Technologycom_jeajaxeventcalendarall versions
Vulnerabilities

Harmis Technology Com Jeajaxeventcalendar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2010-2513
SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.
Published 2010-06-28 · Modified
7.52 PoCEPSS 0.011
CVE-2010-4365
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php.
Published 2010-12-01 · Modified
7.52 PoCEPSS 0.010
CVE-2010-2129
Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.
Published 2010-06-01 · Modified
6.81 PoCEPSS 0.050