Joomla JCal Pro Calendar Component SQL Injection Vulnerability
15 Jun. 2012
Summary
The JCal Pro Calendar component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Vulnerable Systems:
*WebSphere Application Server 8.5
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.