CVE-2009-4670 Information
Feb 14, 2021
cve
Description
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.
Reference
http://secunia.com/advisories/35237 http://www.exploit-db.com/exploits/8797
Share on: