Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

phpScheduleIt < 1.0.1 Reservation.class.php Arbitrary Reservation Modification

Medium

Synopsis

The remote host is vulnerable to a flaw that allows for the bypassing of authentication.

Description

The remote host is running phpScheduleIt, a web-based reservation system written in PHP. According to its banner, this version is reported vulnerable to an undisclosed issue that may allow an attacker to modify or delete phpScheduleIt reservations.

Solution

Upgrade to version 1.0.1 or higher.