CVE-2009-4670
05.03.2010, 18:30
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.Enginsight
| Vendor | Product | Version |
|---|---|---|
| beaussier | roomphplanning | 1.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration