5
CVSSv2

CVE-2010-0380

Published: 22/01/2010 Updated: 25/01/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote malicious users to bypass intended access restrictions and modify application settings via a direct request. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.

Vulnerable Product Search on Vulmon Subscribe to Product

jce-tech php calendars script

Exploits

============================================================================== _ _ _ _ _ _ / \ | | | | / \ | | | | / _ \ | | | | / _ \ | |_| | / ___ \ | |___ | |___ / ___ \ | _ | ...