Unrated severityNVD Advisory· Published Apr 27, 2011· Updated Jun 16, 2026
CVE-2010-4795
CVE-2010-4795
Description
SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a details action to index.php. NOTE: some of these details are obtained from third party information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:joomlaseller:com_jscalendar:1.5.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:joomlaseller:com_jscalendar:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:joomlaseller:com_jscalendar:1.5.4:*:*:*:*:*:*:*
- Range: =1.5.1, =1.5.4
Patches
Vulnerability mechanics
References
6- adv.salvatorefresta.net/JS_Calendar_1.5.1_Joomla_Component_Multiple_Remote_Vulnerabilities-09102010.txtnvdExploit
- www.securityfocus.com/bid/43902nvdExploit
- secunia.com/advisories/41766nvdVendor Advisory
- securityreason.com/securityalert/8223nvd
- www.exploit-db.com/exploits/15224nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/62379nvd
News mentions
0No linked articles in our index yet.