Beaussier
Beaussier Roomphplanning: vulnerabilidades y CVE
Beaussier Roomphplanning tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2009-4671 | Alta (7.5) | 2.3% | — | 5 mar 2010 | Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cookie to a value associated with the admin account. |
| CVE-2009-4670 | Alta (7.5) | 2.3% | — | 5 mar 2010 | admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter. |
| CVE-2009-4669 | Alta (7.5) | 0.93% | — | 5 mar 2010 | Multiple SQL injection vulnerabilities in RoomPHPlanning 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the loginus parameter to Login.php or (2) the Old Password field to changepwd.php, and allow… |
| CVE-2008-6634 | Alta (7.5) | 0.97% | — | 7 abr 2009 | SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idroom parameter to weekview.php. |
| CVE-2008-6633 | Alta (7.5) | 1.2% | — | 7 abr 2009 | SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idresa parameter to resaopen.php. |
| CVE-2008-2488 | Media (6.5) | 1.9% | — | 28 may 2008 | admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts. |