Unrated severityNVD Advisory· Published Apr 27, 2011· Updated Jun 16, 2026
CVE-2010-4794
CVE-2010-4794
Description
Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in a jscalendar action to index.php. NOTE: some of these details are obtained from third party information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:joomlaseller:com_jscalendar:1.5.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:joomlaseller:com_jscalendar:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:joomlaseller:com_jscalendar:1.5.4:*:*:*:*:*:*:*
- (no CPE)range: =1.5.1, =1.5.4
Patches
Vulnerability mechanics
References
6- adv.salvatorefresta.net/JS_Calendar_1.5.1_Joomla_Component_Multiple_Remote_Vulnerabilities-09102010.txtnvdExploitVendor Advisory
- www.exploit-db.com/exploits/15224nvdExploit
- www.securityfocus.com/bid/43902nvdExploit
- secunia.com/advisories/41766nvdVendor Advisory
- securityreason.com/securityalert/8223nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/62378nvd
News mentions
0No linked articles in our index yet.