Required CVE Record Information
Description
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force attack on the embedded password hash.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- securityfocus.com: 75726 vdb-entryx_transferred
- http://packetstormsecurity.com/files/132654/Simple-Online-Planning-Tool-1.3.2-XSS-SQL-Injection-Traversal.html x_transferred
- exploit-db.com: 37604 exploitx_transferred
- seclists.org: 20150708 SOPlanning - Simple Online Planning Tool multiple vulnerabilities mailing-listx_transferred