VYPR

DT Register

by Joomla

CVEs (2)

  • CVE-2016-1000271CriFeb 4, 2019
    risk 0.64cvss 9.8epss 0.02

    Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web server.

  • CVE-2008-3265Jul 24, 2008
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the eventId parameter in a pay_options action to index.php.