Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2021-25024

Disclosure Date: January 17, 2022 (last updated October 07, 2023)
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
Attacker Value
Unknown

CVE-2021-25025

Disclosure Date: January 17, 2022 (last updated November 28, 2024)
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
Attacker Value
Unknown

CVE-2010-4365

Disclosure Date: December 01, 2010 (last updated October 04, 2023)
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php.
0
Attacker Value
Unknown

CVE-2010-2513

Disclosure Date: June 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-2129

Disclosure Date: June 01, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-0796

Disclosure Date: March 02, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the JE Quiz (com_jequizmanagement) component 1.b01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the eid parameter in a question action to index.php.
0
Attacker Value
Unknown

CVE-2010-0795

Disclosure Date: March 02, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an event action to index.php.
0
Attacker Value
Unknown

CVE-2007-3519

Disclosure Date: July 03, 2007 (last updated October 04, 2023)
SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2002-1964

Disclosure Date: December 31, 2002 (last updated October 03, 2023)
Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors.
0