CVE-2008-6736
Last modified
CVE-2008-6736 is a vulnerability of currently unknown severity. Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.. EPSS estimates a 2.20% chance of exploitation in the next 30 days.
Description
Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Circulargenius | Flat Calendar | 1.1 |
References
- http://osvdb.org/51506Exploit
- http://osvdb.org/51506Exploit
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-6736?
How severe is CVE-2008-6736?
How do I fix CVE-2008-6736?
Are you affected by CVE-2008-6736?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
