Security Advisory
CVE-2009-4670
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.