CVE-2008-6356
02.03.2009, 16:30
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb.Enginsight
Vendor | Product | Version |
---|---|---|
donnafontenot | evcal_events_calendar | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration