Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-0730
Description:Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details action to index.php, which is not properly handled by venuedetails.php, and (2) the gigcal_bands_id parameter in a details action to index.php, which is not properly handled by banddetails.php, different vectors than CVE-2009-0726.
Test IDs: 1.3.6.1.4.1.25623.1.0.100004  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-0730
BugTraq ID: 33859
http://www.securityfocus.com/bid/33859
BugTraq ID: 33863
http://www.securityfocus.com/bid/33863
Bugtraq: 20090221 gigCalendar 1.0 (banddetails.php) Joomla Component SQL Injection (Google Search)
http://www.securityfocus.com/archive/1/501176/100/0/threaded
Bugtraq: 20090221 gigCalendar 1.0 (venuedetails.php) Joomla Component SQL Injection (Google Search)
http://www.securityfocus.com/archive/1/501175/100/0/threaded
Bugtraq: 20090221 gigCalendar Joomla Component 1.0 SQL Injection (Google Search)
http://www.securityfocus.com/archive/1/501174/100/0/threaded
XForce ISS Database: gigcalendar-venuedetails-sql-injection(48865)
https://exchange.xforce.ibmcloud.com/vulnerabilities/48865




© 1998-2025 E-Soft Inc. All rights reserved.