CVE-2009-4670
RoomPHPlanning 1.6 - Unauthenticated Arbitrary User and Room Deletion via admin/delitem.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4670. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in RoomPHPlanning v1.6, including SQL injection, authentication bypass, insecure cookie handling, and unauthorized deletion of rooms/users. It provides clear exploitation steps for each vulnerability.
Description
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in RoomPHPlanning v1.6, including SQL injection, authentication bypass, insecure cookie handling, and unauthorized deletion of rooms/users. It provides clear exploitation steps for each vulnerability.