ACal contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an 'ACalAuthenticate' cookie is sent to the 'login.php' script with the value 'inside'. This flaw may lead to an attacker gaining unauthorised access, leading to a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Exploit:
Exploit Public
OSVDB:
Web Related
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.