Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in a jscalendar action to index.php. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JoomlaSeller JS Calendar组件多个跨站脚本攻击漏洞
Vulnerability Description
Joomla!是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla!的JoomlaSeller JS Calendar(com_jscalendar)组件1.5.1和1.5.4版本中存在多个跨站脚本攻击漏洞。远程攻击者可以借助对index.php执行的jscalendar操作中的(1)month参数和(2)year参数注入任意web脚本或者HTML。
CVSS Information
N/A
Vulnerability Type
N/A