Flat Calendar 1.1 - Multiple Administrative Scripts Authentication Bypass Vulnerabilities
Author: Crackers_Child
type: webapps
platform: php
port:
date_added: 2008-06-11
date_updated: 2014-02-26
verified: 1
codes: CVE-2008-6736;OSVDB-51506
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/29662/info
Flat Calendar is prone to multiple authentication-bypass vulnerabilities because it fails to perform adequate authentication checks.
An attacker can exploit these issues to gain unauthorized access to the application and make arbitrary changes to its configuration. This may lead to further attacks.
Flat Calendar 1.1 is vulnerable; other versions may also be affected.
http://www.example.com/calender_path/admin/add.php
http://www.example.com/calender_path/admin/deleteEvent.php?eventNumber=[EVENTNUMBERid]