CVE-2008-6736 Information
Feb 14, 2021
cve
Description
Flat Calendar 1.1 does not properly restrict access to administrative functions which allows remote attackers to (1) add new events via calAdd.php as reachable from admin/add.php or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product’s security documentation.
Reference
http://osvdb.org/51506 http://www.securityfocus.com/archive/1/493278/100/0/threaded http://www.securityfocus.com/bid/29662 https://exchange.xforce.ibmcloud.com/vulnerabilities/43039
Share on: