PoC Index

CVE-2009-4670

HIGH 7.5EPSS 2.3%

admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.27% chance of exploitation in the next 30 days, 82th percentile
Published
2010-03-05
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related