CVE-2009-4670

Publication date

2010-03-05 18:00:00

Family

mitre

State

PUBLISHED

Description

admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.