Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/530891/100/0/threaded | mailing list exploit vdb entry third party advisory |
http://bazaar.launchpad.net/~eventum-developers/eventum/trunk/revision/4666 | third party advisory patch |
https://www.htbridge.com/advisory/HTB23198 | third party advisory exploit |
https://bugs.launchpad.net/eventum/+bug/1271499 | issue tracking exploit third party advisory |