install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application settings via a direct request. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the products installation documentation.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php_calendars_script | Jce-tech | * | * |