[~] Flat Calendar By-Pass / Html inj / XSS Multiple Vulns. [~] [~]---------------------------------------------------------- [~] Discovered By: ZoRLu msn: trt-turk@hotmail.com [~] [~] Date: 23.04.09 [~] [~] Home: yildirimordulari.com / z0rlu.blogspot.com [~] [~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( ( [~] [~] N0T: Alem Hep Hacker Olmus :P [~] ----------------------------------------------------------- By-Pass http://www.ossi-im-inter.net/calendar/admin/add.php Html inj: you go here: http://www.ossi-im-inter.net/calendar/admin/add.php write title after write your html code to description example: http://www.ossi-im-inter.net/calendar/viewEvent.php?eventNumber=561 Xss you go here: http://www.ossi-im-inter.net/calendar/admin/add.php write title anything ( example salla :D ) write to description this code: "> after go your calender [~]---------------------------------------------------------------------- [~] Greetz tO: packetstormsecurity.org & Scriptorium & Aycanbey & PhantomOrchid & Nicx & Dr.Ly0n & Cyber-Zone & AlpHaNiX & Stack [~] [~] woltaj.org / www.experl.com / dafgamers.com [~] [~]----------------------------------------------------------------------